CVE-2019-19542: XSS
Published Dec 26, 2019
·Updated
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.
Affected Software
1 affected component
Cridio Listingpro Wordpress<2.0.14.2
Event History
Dec 26, 2019
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19542?
CVE-2019-19542 is classified as a medium severity vulnerability due to its potential for exploitation via persistent XSS.
2
How do I fix CVE-2019-19542?
To fix CVE-2019-19542, update the ListingPro theme to version 2.0.14.2 or later.
3
What type of vulnerability is CVE-2019-19542?
CVE-2019-19542 is a Persistent Cross-Site Scripting (XSS) vulnerability.
4
Which versions of ListingPro are affected by CVE-2019-19542?
CVE-2019-19542 affects ListingPro theme versions before 2.0.14.2.
5
Can CVE-2019-19542 impact user data?
Yes, due to its persistent nature, CVE-2019-19542 can be used to execute malicious scripts that may compromise user data.