"value":"Multiple cross-site request forgery (CSRF) vulnerabilities in the yURL ReTwitt plugin 1.4 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) yurl_login or (2) yurl_anchor parameter in the yurl page to wp-admin/options-general.php."
},
{
"lang":"es",
"value":"M\u00faltiples vulnerabilidades de CSRF en el plugin yURL ReTwitt 1.4 y anteriores para WordPress permiten a atacantes remotos secuestrar la autenticaci\u00f3n de los administradores para peticiones que provocan ataques de XSS a trav\u00e9s del par\u00e1metro (1) yurl_login o (2) yurl_anchor en la p\u00e1gina yurl hacia wp-admin/options-general.php."