.. / CVE-2019-20210

Exploit for WordPress CTHthemes - Cross-Site Scripting (CVE-2019-20210)

Description:

WordPress CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes contain reflected cross-site scripting vulnerabilities via a search query.

Nuclei Template

View the template here CVE-2019-20210.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-20210.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2019-20210
https://cxsecurity.com/issue/WLB-2019120112
https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727
https://wpvulndb.com/vulnerabilities/10018
https://wpscan.com/vulnerability/10013