Record summary

CVE-2019-20210 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress CTHthemes - Cross-Site ScriptingCVSS 6.1

WordPress CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes contain reflected cross-site scripting vulnerabilities via a search query.

Impact

Successful exploitation of this vulnerability can lead to session hijacking, defacement of the website, theft of sensitive information, or the installation of malware on the victim's system.

Remediation

Update to the latest version of the WordPress CTHthemes plugin, which includes a fix for this vulnerability.

WeaknessesCWE-79
Authorsedoardottt
Template tagscvecve2019wp-themewpscanwordpresscitybookxsscththemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cththemes:citybook:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

10