"value":"The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well"
"value":"El complemento de WordPress Popup Manager hasta la versi\u00f3n 1.6.6 no tiene autorizaci\u00f3n ni verificaci\u00f3n CSRF al crear/actualizar ventanas emergentes, y le falta sanitizaci\u00f3n y escape, lo que podr\u00eda permitir a atacantes no autenticados crear ventanas emergentes arbitrarias y agregar tambi\u00e9n payloads XSS almacenados."