First published: Tue Nov 26 2019(Updated: )
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho Lead Magnet | =1.6.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19306 is a vulnerability in the Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress that allows XSS (Cross-Site Scripting) attacks via the module EditShortcode or LayoutName.
CVE-2019-19306 affects Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress and allows attackers to execute malicious scripts in a victim's browser.
CVE-2019-19306 has a severity rating of medium with a CVSS score of 5.4.
To fix CVE-2019-19306, it is recommended to update the Zoho CRM Lead Magnet plugin to the latest version.
You can find more information about CVE-2019-19306 on the following references: [link1], [link2], [link3].