"value":"The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers"
"value":"El complemento RSS Feed Widget de WordPress anterior a la versi\u00f3n 3.0.1 no escapa al par\u00e1metro $_SERVER['REQUEST_URI'] antes de mostrarlo nuevamente en un atributo, lo que podr\u00eda generar Cross Site Scripting reflejado en navegadores web antiguos."