CVE-2019-20211: Cththemes Citybook
Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
Affected products
- Cththemes Citybook: before 2.3.4 (fixed in 2.3.4)
- Cththemes Easybook: before 1.2.2 (fixed in 1.2.2)
- Cththemes Townhub: before 1.0.6 (fixed in 1.0.6)
Published 2020-01-13. Last modified 2026-06-17.