"value":"The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin"
"value":"El complemento WP Matterport Shortcode de WordPress anterior a 2.1.7 no escapa a la variable del servidor PHP_SELF cuando la genera en atributos, lo que genera problemas de Cross-Site Scripting reflejados que podr\u00edan usarse contra usuarios con privilegios elevados, como el administrador."