Skip to main content

Vendor/product archive

vcita / online_booking_&_scheduling_calendar CVEs

Beta · best-effort

19 CVEs tagged to vcita / online_booking_&_scheduling_calendar1 Critical, 5 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2025-54677

Published Aug 20, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Maliciou…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54676

Published Aug 14, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-sch…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54356

Published Dec 16, 2024

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.T…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9872

Published Dec 6, 2024

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vc…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47638

Published Oct 5, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-sch…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37262

Published Jul 22, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37499

Published Jul 9, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Path Trave…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5791

Published Jun 22, 2024

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35761

Published Jun 21, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5859

Published Jun 21, 2024

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all versions up to, a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39992

Published Sep 4, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2414

Published Jun 9, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vc…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2416

Published Jun 3, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_c…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2415

Published Jun 3, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vc…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2299

Published Jun 3, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/a…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2298

Published Jun 3, 2023

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1