"value":"The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping"
"value":"El plugin Subscribers Text Counter WordPress anterior a la versi\u00f3n 1.7.1 no dispone de una comprobaci\u00f3n CSRF al actualizar sus ajustes, lo que podr\u00eda permitir a los atacantes hacer que un administrador que ha iniciado sesi\u00f3n los cambie mediante un ataque CSRF, que tambi\u00e9n llevar\u00eda a Cross-Site Scripting (XSS) Almacenado debido a la falta de sanitizaci\u00f3n y escapes."