CVE-2019-20209: Cththemes Citybook
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
Affected products
- Cththemes Citybook: before 2.3.4 (fixed in 2.3.4)
- Cththemes Easybook: before 1.2.2 (fixed in 1.2.2)
- Cththemes Townhub: before 1.0.6 (fixed in 1.0.6)
Published 2020-01-13. Last modified 2026-06-17.