CityBook [citybook] < 2.4.4
unknownUnauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Vlad Vector in WordPress CityBook premium theme (versions <= 2.4.3).
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Jun 19, 2020
theme
15 known security issues reported for the Citybook WordPress theme. Most recent disclosed Jun 19, 2020.
Running Citybook on your site? Check whether your installed version is affected.
Scan your site freeUnauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Vlad Vector in WordPress CityBook premium theme (versions <= 2.4.3).
The CityBook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'distance', 'address_lat', and 'address_lng' parameters in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
The CityBook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'distance', 'address_lat', and 'address_lng' parameters in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
[en] An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used.
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Websi...
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
Multiple vulnerabilities (Reflected XSS, Persistent XSS & IDOR) found by m0ze in WordPress CityBook theme (versions <= 2.3.3).
Multiple vulnerabilities found by m0ze in WordPress CityBook premium theme (versions <= 2.3.3).
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecified authenticated users to delete any page/post/listing via insecure Direct Object Reference (IDOR).
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
Unauthenticated Reflected XSS vulnerability was discovered in the «CityBook - Directory & Listing WordPress Theme», tested version — v2.4.3. Edit (WPScanTeam) June 17th, 2020 - Confirmed & Escalated to Envato June 18th, 2020 - v2.4.4 released, fixing the issue
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free