Vulnerability Description
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cththemes | Citybook | < 2.3.4 |
| Cththemes | Easybook | < 1.2.2 |
| Cththemes | Townhub | < 1.0.6 |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/issue/WLB-2019120110ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120111ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120112ExploitThird Party Advisory
- https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727Third Party Advisory
- https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622Third Party Advisory
- https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10013Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10014Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10018Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120110ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120111ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120112ExploitThird Party Advisory
- https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727Third Party Advisory
- https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622Third Party Advisory
- https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571Third Party Advisory
FAQ
What is CVE-2019-20211?
CVE-2019-20211 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, ...
How severe is CVE-2019-20211?
CVE-2019-20211 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20211?
Check the references section above for vendor advisories and patch information. Affected products include: Cththemes Citybook, Cththemes Easybook, Cththemes Townhub.