Persistent XSS in ListingPro Theme by WordPress
CVE-2019-19541

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 December 2019

Summary

The ListingPro theme for WordPress is vulnerable to persistent cross-site scripting (XSS) attacks. This vulnerability is found in the Best Day/Night field on the new listing submission page, allowing attackers to inject malicious scripts. When users submit listings, the injected scripts can be executed in the context of other users, potentially compromising additional accounts and sensitive information. It's crucial for WordPress users employing the ListingPro theme to update to version 2.0.14.2 or higher to mitigate this security risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.