The CTHthemes CityBook prior to 2.3.4, TownHub prior to 1.0.6, and EasyBook prior to 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cththemes citybook |
||
cththemes easybook |
||
cththemes townhub |