VulnerabilityModified
CVE-2019-20212
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
MEDIUM 6.1EPSS 2.58%
Does this matter?
Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.
Description
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cththemes/citybook · cththemes/easybook · cththemes/townhub
- Source
- cve@mitre.org
References
- https://cxsecurity.com/issue/WLB-2019120110Exploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120111Exploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120112Exploit, Third Party Advisory
- https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727Third Party Advisory
- https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622Third Party Advisory
- https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10013Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10014Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10018Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120110Exploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120111Exploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120112Exploit, Third Party Advisory
- https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727Third Party Advisory
- https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622Third Party Advisory
- https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10013Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10014Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10018Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.