CVE-2019-20210
WordPress CTHthemes - Cross-Site Scripting
Record summary
CVE-2019-20210 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress CTHthemes - Cross-Site ScriptingCVSS 6.1
WordPress CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes contain reflected cross-site scripting vulnerabilities via a search query.
Impact
Successful exploitation of this vulnerability can lead to session hijacking, defacement of the website, theft of sensitive information, or the installation of malware on the victim's system.
Remediation
Update to the latest version of the WordPress CTHthemes plugin, which includes a fix for this vulnerability.
Source: ProjectDiscovery