"value":"The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well."
"value":"El complemento de WordPress WP Total Hacks hasta 4.7.2 no impide que los usuarios con privilegios bajos modifiquen la configuraci\u00f3n del complemento. Esto podr\u00eda permitir a usuarios como suscriptores realizar ataques de Stored Cross-Site Scripting contra otros usuarios, como administradores, debido a la falta de sanitizaci\u00f3n y tambi\u00e9n de escape."