Reflected XSS Vulnerability in CTHthemes CityBook, TownHub and EasyBook Themes
CVE-2019-20210
6.1MEDIUM
Summary
The CTHthemes CityBook, TownHub, and EasyBook themes for WordPress are susceptible to reflected Cross-Site Scripting (XSS) due to improper handling of user input in search queries. Attackers could exploit this vulnerability to inject malicious scripts, potentially compromising user data and session integrity. It is crucial for users of these themes to update to the latest versions to safeguard against potential attacks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved