theme

Easybook Vulnerabilities

8 known security issues reported for the Easybook WordPress theme. Most recent disclosed Jan 13, 2020.

2 high 2 medium

Running Easybook on your site? Check whether your installed version is affected.

Scan your site free

EasyBook [easybook] < 1.2.2

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Jan 13, 2020

CVE-2019-20209 on NVD →

EasyBook [easybook] < 1.2.2

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Jan 13, 2020

CVE-2019-20210 on NVD →

EasyBook [easybook] < 1.2.2

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Websi...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Jan 13, 2020

CVE-2019-20211 on NVD →

EasyBook [easybook] < 1.2.2

unknown

[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Jan 13, 2020

CVE-2019-20212 on NVD →

CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting

high

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.

CVSS:
7.2
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Dec 27, 2019

CVE-2019-20212 on NVD →

CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting

high

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.

CVSS:
7.2
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Dec 27, 2019

CVE-2019-20211 on NVD →

CTHthemes CityBook < 2.3.4, TownHub < 1.0.6, EasyBook < 1.2.2 Themes - Authenticated Post Deleition via IDOR

medium

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecified authenticated users to delete any page/post/listing via insecure Direct Object Reference (IDOR).

CVSS:
6.5
Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Dec 27, 2019

CVE-2019-20209 on NVD →

CTHthemes CityBook Theme < 2.3.4, TownHub Theme < 1.0.6, EasyBook Theme < 1.2.2 - Cross-Site Scripting

medium

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.

CVSS:
6.1
Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Dec 27, 2019

CVE-2019-20210 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database