"value":"The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission"
},
{
"lang":"es",
"value":"El plugin Contact Form Submissions de WordPress versiones anteriores a 1.7.3, no sanea ni escapa de los campos adicionales en las peticiones de formularios de contacto antes de mostrarlos en el env\u00edo correspondiente. Como resultado, un atacante no autenticado podr\u00eda llevar a cabo ataques de tipo Cross-Site Scripting contra los administradores que vean el env\u00edo malicioso"