CVE-2019-19541: XSS
Published Dec 26, 2019
·Updated
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.
Affected Software
1 affected component
Cridio Listingpro Wordpress<2.0.14.2
Event History
Dec 26, 2019
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19541?
CVE-2019-19541 is classified as a high severity vulnerability due to its potential for persistent cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-19541?
To fix CVE-2019-19541, update the ListingPro theme to version 2.0.14.2 or later.
3
What software is affected by CVE-2019-19541?
CVE-2019-19541 affects the ListingPro theme for WordPress versions prior to 2.0.14.2.
4
What kind of attack can be executed using CVE-2019-19541?
CVE-2019-19541 allows for persistent cross-site scripting (XSS) attacks by exploiting the Best Day/Night field on the new listing submit page.
5
Is it safe to use older versions of the ListingPro theme after CVE-2019-19541?
No, using older versions of the ListingPro theme is unsafe as they are vulnerable to persistent XSS attacks.