"value":"The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin"
},
{
"lang":"es",
"value":"El complemento wpb-show-core de WordPress anterior a 2.6 no desinfecta ni escapa algunos par\u00e1metros antes de devolverlos a la p\u00e1gina, lo que genera un cross-site scripting reflejado que podr\u00eda usarse contra usuarios con privilegios elevados, como el administrador."