CVE-2019-19540: XSS
Published Dec 26, 2019
·Updated
The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.
Affected Software
1 affected component
Cridio Listingpro Wordpress<2.0.14.2
Event History
Dec 26, 2019
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19540?
CVE-2019-19540 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-19540?
To fix CVE-2019-19540, upgrade the ListingPro theme to version 2.0.14.2 or later.
3
What type of vulnerability is CVE-2019-19540?
CVE-2019-19540 is a reflected cross-site scripting (XSS) vulnerability.
4
What are the potential impacts of CVE-2019-19540?
The potential impacts of CVE-2019-19540 include unauthorized script execution in the context of the user’s browser.
5
Which versions of the ListingPro theme are affected by CVE-2019-19540?
CVE-2019-19540 affects all versions of the ListingPro theme prior to version 2.0.14.2.