"value":"The WCFM \u2013 Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks"
"value":"El plugin WCFM - Frontend Manager for WooCommerce junto con Bookings Subscription Listings Compatible de WordPress versiones anteriores a 6.5.12, cuando es usado en combinaci\u00f3n con otro plugin WCFM - WooCommerce Multivendor como WCFM - WooCommerce Multivendor Marketplace, no escapa el par\u00e1metro withdrawal_vendor antes de usarlo en una sentencia SQL, permitiendo a usuarios poco privilegiados como los Suscriptores llevar a cabo ataques de inyecci\u00f3n SQL"