Vulnerability Description
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cththemes | Citybook | < 2.3.4 |
| Cththemes | Easybook | < 1.2.2 |
| Cththemes | Townhub | < 1.0.6 |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/issue/WLB-2019120110ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120111ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120112ExploitThird Party Advisory
- https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727Third Party Advisory
- https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622Third Party Advisory
- https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10013Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10014Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10018Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120110ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120111ExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2019120112ExploitThird Party Advisory
- https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727Third Party Advisory
- https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622Third Party Advisory
- https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571Third Party Advisory
FAQ
What is CVE-2019-20212?
CVE-2019-20212 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
How severe is CVE-2019-20212?
CVE-2019-20212 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20212?
Check the references section above for vendor advisories and patch information. Affected products include: Cththemes Citybook, Cththemes Easybook, Cththemes Townhub.