Medium severity5.4NVD Advisory· Published Nov 26, 2019· Updated Jun 17, 2026
CVE-2019-19306
CVE-2019-19306
Description
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:zoho:lead_magnet:1.6.9.1:*:*:*:*:wordpress:*:*
- WordPress/Zoho CRM Lead Magnet plugindescription
- Range: <1.6.9.1
Patches
Vulnerability mechanics
References
4- cybersecurityworks.com/zerodays/cve-2019-19306-zoho.htmlnvdExploitThird Party Advisory
- github.com/cybersecurityworks/Disclosed/issues/16nvdExploitThird Party Advisory
- wordpress.org/plugins/zoho-crm-forms/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/9919nvdThird Party Advisory
News mentions
0No linked articles in our index yet.