{ "schema_version": "1.4.0", "id": "GHSA-wp3p-4fj8-x356", "modified": "2022-05-24T17:06:06Z", "published": "2022-05-24T17:06:06Z", "aliases": [ "CVE-2019-20209" ], "details": "The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20209" }, { "type": "WEB", "url": "https://cxsecurity.com/issue/WLB-2019120110" }, { "type": "WEB", "url": "https://cxsecurity.com/issue/WLB-2019120111" }, { "type": "WEB", "url": "https://cxsecurity.com/issue/WLB-2019120112" }, { "type": "WEB", "url": "https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727" }, { "type": "WEB", "url": "https://themeforest.net/item/easybook-directory-listing-wordpress-theme/23206622" }, { "type": "WEB", "url": "https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571" }, { "type": "WEB", "url": "https://wpvulndb.com/vulnerabilities/10013" }, { "type": "WEB", "url": "https://wpvulndb.com/vulnerabilities/10014" }, { "type": "WEB", "url": "https://wpvulndb.com/vulnerabilities/10018" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-01-13T18:15:00Z" } }