📦 Online Booking \& Scheduling Calendar

by Vcita

🔍 What is Online Booking \& Scheduling Calendar?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54677

CRITICAL CVSS 9.1 Aug 20, 2025

This vulnerability allows attackers to upload malicious files to WordPress sites using the vcita Online Booking & Scheduling Calendar plugin. Attackers can upload dangerous file types like PHP scripts...

CVE-2025-67472

HIGH CVSS 8.8 Dec 9, 2025

This CSRF vulnerability in vcita's WordPress booking plugin allows attackers to trick authenticated administrators into performing unintended actions, such as changing plugin settings or potentially c...

CVE-2024-47638

HIGH CVSS 7.1 Oct 5, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the vCita Online Booking & Scheduling Calendar WordPress plugin. When users visit a specially crafted URL, t...

CVE-2024-37262

HIGH CVSS 7.1 Jul 22, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the vCita Online Booking & Scheduling Calendar WordPress plugin. When users visit a specially crafted URL, t...

CVE-2024-5791

HIGH CVSS 7.2 Jun 22, 2024

This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'wp_id' parameter in the vcita WordPress plugin. The scripts execute when users access the WordPress admin dashb...

CVE-2023-2298

HIGH CVSS 7.2 Jun 3, 2023

This stored XSS vulnerability in the vcita WordPress plugin allows unauthenticated attackers to inject malicious JavaScript via the 'business_id' parameter. The injected scripts execute whenever users...

CVE-2025-67559

MEDIUM CVSS 5.4 Dec 9, 2025

This CVE describes a Missing Authorization vulnerability in the vcita Online Booking & Scheduling Calendar WordPress plugin that allows attackers to exploit incorrectly configured access control secur...

CVE-2025-54676

MEDIUM CVSS 6.5 Aug 14, 2025

This stored cross-site scripting (XSS) vulnerability in the vcita Online Booking & Scheduling Calendar WordPress plugin allows attackers to inject malicious scripts into web pages that are then execut...

CVE-2024-9872

MEDIUM CVSS 5.4 Dec 6, 2024

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to inject malicious scripts and modify plugin settings without proper authorization. It affects all WordP...

CVE-2024-37499

MEDIUM CVSS 6.5 Jul 9, 2024

This path traversal vulnerability in the vCita Online Booking & Scheduling Calendar WordPress plugin allows attackers to access files outside the intended directory. It affects WordPress sites using t...

CVE-2024-35761

MEDIUM CVSS 6.5 Jun 21, 2024

This stored XSS vulnerability in the vCita Online Booking & Scheduling Calendar WordPress plugin allows attackers to inject malicious scripts into web pages. When users view affected pages, the script...