Persistent XSS in ListingPro Theme for WordPress
CVE-2019-19542
5.4MEDIUM
What is CVE-2019-19542?
The ListingPro theme prior to version 2.0.14.2 for WordPress is susceptible to a Persistent Cross-Site Scripting (XSS) vulnerability. This flaw arises from improper handling of the 'Good For' field on the new listing submission page, allowing attackers to inject malicious scripts that get stored and later executed in the web browser of any user who views the affected listings. This poses a significant risk to user data and website integrity.