theme

Citybook Vulnerabilities

15 known security issues reported for the Citybook WordPress theme. Most recent disclosed Jun 19, 2020.

2 high 3 medium

Running Citybook on your site? Check whether your installed version is affected.

Scan your site free

CityBook [citybook] < 2.4.4

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Vlad Vector in WordPress CityBook premium theme (versions <= 2.4.3).

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Jun 19, 2020

CityBook <= 2.4.3 - Reflected Cross-Site Scripting

medium

The CityBook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'distance', 'address_lat', and 'address_lng' parameters in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

CVSS:
6.1
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jun 17, 2020

CityBook [citybook] < 2.4.4

unknown

The CityBook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'distance', 'address_lat', and 'address_lng' parameters in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Jun 17, 2020

CityBook [citybook] < 2.3.4

unknown

[en] An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 23, 2020

CVE-2019-16515 on NVD →

CityBook [citybook] < 2.3.4

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 13, 2020

CVE-2019-20209 on NVD →

CityBook [citybook] < 2.3.4

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 13, 2020

CVE-2019-20210 on NVD →

CityBook [citybook] < 2.3.4

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Websi...

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 13, 2020

CVE-2019-20211 on NVD →

CityBook [citybook] < 2.3.4

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 13, 2020

CVE-2019-20212 on NVD →

CityBook [citybook] < 2.3.4

unknown

Multiple vulnerabilities (Reflected XSS, Persistent XSS & IDOR) found by m0ze in WordPress CityBook theme (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 9, 2020

CityBook [citybook] < 2.3.4

unknown

Multiple vulnerabilities found by m0ze in WordPress CityBook premium theme (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 9, 2020

CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting

high

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.

CVSS:
7.2
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Dec 27, 2019

CVE-2019-20212 on NVD →

CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting

high

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.

CVSS:
7.2
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Dec 27, 2019

CVE-2019-20211 on NVD →

CTHthemes CityBook < 2.3.4, TownHub < 1.0.6, EasyBook < 1.2.2 Themes - Authenticated Post Deleition via IDOR

medium

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecified authenticated users to delete any page/post/listing via insecure Direct Object Reference (IDOR).

CVSS:
6.5
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Dec 27, 2019

CVE-2019-20209 on NVD →

CTHthemes CityBook Theme < 2.3.4, TownHub Theme < 1.0.6, EasyBook Theme < 1.2.2 - Cross-Site Scripting

medium

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.

CVSS:
6.1
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Dec 27, 2019

CVE-2019-20210 on NVD →

CityBook [citybook] < 2.4.4

unknown

Unauthenticated Reflected XSS vulnerability was discovered in the &laquo;CityBook - Directory &amp; Listing WordPress Theme&raquo;, tested version &mdash; v2.4.3. Edit (WPScanTeam) June 17th, 2020 - Confirmed &amp; Escalated to Envato June 18th, 2020 - v2.4.4 released, fixing the issue

Affected:
up to 2.4.4
Fixed in:
2.4.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database