TownHub <= 1.2.9 - Reflected Cross-Site Scripting
medium
The TownHub theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3.0
- Disclosed:
- Jun 19, 2020
TownHub [townhub] < 1.3.0
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (VLΛD VΞCTOR) in WordPress TownHub premium theme (versions <= 1.2.9).
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Jun 19, 2020
TownHub [townhub] < 1.3.0
unknown
The TownHub theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Jun 19, 2020
TownHub [townhub] < 1.0.6
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 13, 2020
CVE-2019-20209 on NVD →
TownHub [townhub] < 1.0.6
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 13, 2020
CVE-2019-20210 on NVD →
TownHub [townhub] < 1.0.6
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Websi...
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 13, 2020
CVE-2019-20211 on NVD →
TownHub [townhub] < 1.0.6
unknown
[en] The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 13, 2020
CVE-2019-20212 on NVD →
TownHub [townhub] < 1.0.6
unknown
Unauthenticated Cross-Site Scripting (XSS) vulnerability found by m0ze in WordPress TownHub premium theme (versions <= 1.0.5).
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 3, 2020
TownHub [townhub] < 1.0.6
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress TownHub premium theme (versions <= 1.0.5).
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 3, 2020
CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting
high
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
- CVSS:
- 7.2
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Dec 27, 2019
CVE-2019-20212 on NVD →
CTHthemes CityBook <= 2.3.3, TownHub <= 1.0.5, and EasyBook <= 1.2.1 - Stored Cross-Site Scripting
high
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
- CVSS:
- 7.2
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Dec 27, 2019
CVE-2019-20211 on NVD →
CTHthemes CityBook < 2.3.4, TownHub < 1.0.6, EasyBook < 1.2.2 Themes - Authenticated Post Deleition via IDOR
medium
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecified authenticated users to delete any page/post/listing via insecure Direct Object Reference (IDOR).
- CVSS:
- 6.5
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Dec 27, 2019
CVE-2019-20209 on NVD →
CTHthemes CityBook Theme < 2.3.4, TownHub Theme < 1.0.6, EasyBook Theme < 1.2.2 - Cross-Site Scripting
medium
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
- CVSS:
- 6.1
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Dec 27, 2019
CVE-2019-20210 on NVD →
TownHub [townhub] < 1.3.0
unknown
Unauthenticated Reflected XSS vulnerability was discovered in the «TownHub - Directory & Listing WordPress Theme», tested version — v1.2.9.
Edit (WPScanTeam)
June 17th, 2020 - Confirmed & Escalated to Envato
June 18th, 2020 - v1.3.0 released, fixing the issue
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database