Skip to main content

Vendor archive

vcita CVEs

Beta · best-effort

30 CVEs tagged to vendor vcita1 Critical, 5 High, 24 Medium, 0 Low, 0 Unrated.

CVE-2025-54677

Published Aug 20, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Maliciou…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54676

Published Aug 14, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-sch…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13702

Published Mar 26, 2025

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and 'vCitaSchedulingCalendar' short…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13703

Published Mar 13, 2025

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() functi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54356

Published Dec 16, 2024

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.T…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9872

Published Dec 6, 2024

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vc…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47638

Published Oct 5, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-sch…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37262

Published Jul 22, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37499

Published Jul 9, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Path Trave…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5791

Published Jun 22, 2024

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35761

Published Jun 21, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5859

Published Jun 21, 2024

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all versions up to, a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39992

Published Sep 4, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2414

Published Jun 9, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vc…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2416

Published Jun 3, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_c…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2415

Published Jun 3, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vc…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2405

Published Jun 3, 2023

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This is due to missing nonce validat…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2404

Published Jun 3, 2023

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.2 due to ins…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2303

Published Jun 3, 2023

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.5. This is due to missing non…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2