Vulnerabilities > Cththemes > Easybook > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-13 CVE-2019-20209 Authorization Bypass Through User-Controlled Key vulnerability in Cththemes Citybook, Easybook and Townhub
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
network
low complexity
cththemes CWE-639
7.5