CVE-2019-20211
Summary
| CVE | CVE-2019-20211 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-13 18:15:00 UTC |
| Updated | 2020-01-14 15:35:00 UTC |
| Description | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cththemes | Citybook | All | All | All | All |
| Application | Cththemes | Citybook | All | All | All | All |
| Application | Cththemes | Easybook | All | All | All | All |
| Application | Cththemes | Easybook | All | All | All | All |
| Application | Cththemes | Townhub | All | All | All | All |
| Application | Cththemes | Townhub | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EasyBook < 1.2.2 - Multiple Vulnerabilities | MISC | wpvulndb.com | Third Party Advisory |
| TownHub < 1.0.6 - Multiple Vulnerabilities | MISC | wpvulndb.com | Third Party Advisory |
| TownHub - Directory & Listing WordPress Theme v1.0.2 Multiple Vulnerabilities - CXSecurity.com | MISC | cxsecurity.com | Exploit, Third Party Advisory |
| CityBook - Directory & Listing WordPress Theme v2.2.2 Multiple Vulnerabilities - CXSecurity.com | MISC | cxsecurity.com | Exploit, Third Party Advisory |
| CityBook - Directory & Listing WordPress Theme by cththemes | ThemeForest | MISC | themeforest.net | Third Party Advisory |
| CityBook < 2.3.4 - Multiple Vulnerabilities | MISC | wpvulndb.com | Third Party Advisory |
| EasyBook – Directory & Listing WordPress Theme by cththemes | ThemeForest | MISC | themeforest.net | Third Party Advisory |
| EasyBook – Directory & Listing WordPress Theme v1.2.1 Multiple Vulnerabilities - CXSecurity.com | MISC | cxsecurity.com | Exploit, Third Party Advisory |
| TownHub - Directory & Listing WordPress Theme by cththemes | ThemeForest | MISC | themeforest.net | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.