Persistent XSS in ListingPro Theme for WordPress
CVE-2019-19542

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 December 2019

Summary

The ListingPro theme prior to version 2.0.14.2 for WordPress is susceptible to a Persistent Cross-Site Scripting (XSS) vulnerability. This flaw arises from improper handling of the 'Good For' field on the new listing submission page, allowing attackers to inject malicious scripts that get stored and later executed in the web browser of any user who views the affected listings. This poses a significant risk to user data and website integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.