"value":"The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message"
"value":"El complemento Chat Bubble de WordPress anterior a 2.3 no sanitiza y escapa a algunos par\u00e1metros de contacto, lo que podr\u00eda permitir a atacantes no autenticados configurar Cross-Site Scripting payloads almacenados en ellos, que se activar\u00e1n cuando un administrador vea el mensaje de contacto relacionado."