CVE-2019-20209 - Cththemes Citybook, Cththemes Easybook and Cththemes Townhub

Critical 7.5

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

Affected software

Cththemes Citybook

Cththemes Easybook

Cththemes Townhub

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.