"value":"The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link"
},
{
"lang":"es",
"value":"El plugin Popup Builder de WordPress versiones anteriores a 4.1.1, no sanea ni escapa del par\u00e1metro sgpb-subscription-popup-id antes de usarlo en una sentencia SQL en el panel de administraci\u00f3n de All Subscribers, conllevando a una inyecci\u00f3n SQL, que tambi\u00e9n podr\u00eda usarse para llevar a cabo un ataque de tipo Cross-Site Scripting Reflejado contra un administrador conectado que abra un enlace malicioso"