"value":"The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks."
"value":"El complemento de WordPress tagDiv Composer anterior a 4.2, utilizado como complemento de los temas Newspaper y Newsmag de tagDiv, no tiene autorizaci\u00f3n en una ruta REST y no valida ni escapa algunos par\u00e1metros al devolverlos, lo que podr\u00eda permitir a usuarios no autenticados realizar ataques de Cross-Site Scripting almacenado."