EasyBook [easybook] < 1.2.2
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Jan 13, 2020
CVE-2019-20209 on NVD →
EasyBook [easybook] < 1.2.2
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Jan 13, 2020
CVE-2019-20210 on NVD →
EasyBook [easybook] < 1.2.2
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Websi...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Jan 13, 2020
CVE-2019-20211 on NVD →
EasyBook [easybook] < 1.2.2
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Jan 13, 2020
CVE-2019-20212 on NVD →
CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting
high
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
- CVSS:
- 7.2
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Dec 27, 2019
CVE-2019-20212 on NVD →
CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting
high
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
- CVSS:
- 7.2
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Dec 27, 2019
CVE-2019-20211 on NVD →
CTHthemes CityBook < 2.3.4, TownHub < 1.0.6, EasyBook < 1.2.2 Themes - Authenticated Post Deleition via IDOR
medium
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecified authenticated users to delete any page/post/listing via insecure Direct Object Reference (IDOR).
- CVSS:
- 6.5
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Dec 27, 2019
CVE-2019-20209 on NVD →
CTHthemes CityBook Theme < 2.3.4, TownHub Theme < 1.0.6, EasyBook Theme < 1.2.2 - Cross-Site Scripting
medium
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
- CVSS:
- 6.1
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Dec 27, 2019
CVE-2019-20210 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database