CVE-2019-19306: XSS
Published Nov 26, 2019
·Updated
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
Affected Software
1 affected component
Zoho Lead Magnet Wordpress=1.6.9.1
Event History
Nov 26, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is CVE-2019-19306?
CVE-2019-19306 is a vulnerability in the Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress that allows XSS (Cross-Site Scripting) attacks via the module EditShortcode or LayoutName.
2
How does CVE-2019-19306 affect Zoho CRM Lead Magnet plugin?
CVE-2019-19306 affects Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress and allows attackers to execute malicious scripts in a victim's browser.
3
What is the severity of CVE-2019-19306?
CVE-2019-19306 has a severity rating of medium with a CVSS score of 5.4.
4
How can I fix CVE-2019-19306?
To fix CVE-2019-19306, it is recommended to update the Zoho CRM Lead Magnet plugin to the latest version.
5
Where can I find more information about CVE-2019-19306?
You can find more information about CVE-2019-19306 on the following references: [link1], [link2], [link3].