Extension WordPress

Vulnérabilités Online Booking & Scheduling Calendar for WordPress by vcita

Cette page rassemble les failles publiées pour Online Booking & Scheduling Calendar for WordPress by vcita, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
0Critiques
19Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Online Booking & Scheduling Calendar for WordPress by vcita

19 fiches

CVE-2025-67559 Moyenne · 4,3
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 – Missing Authorization

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.5.5. This makes it…

Versions affectées

*-4.5.5

Correctif

4.6.0

Publication

12/11/2025

CVE-2025-67472 Moyenne · 4,3
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 – Cross-Site Request Forgery

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.5. This is due to missing or incorrect nonce validation on a…

Versions affectées

*-4.5.5

Correctif

4.6.0

Publication

12/11/2025

CVE-2025-54677 Élevée · 8,8
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 – Authenticated (Author+) Arbitrary File Upload

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.5.3. This makes it possible for…

Versions affectées

*-4.5.3

Correctif

4.5.5

Publication

14/08/2025

CVE-2025-54676 Moyenne · 6,4
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.5.3

Correctif

4.5.5

Publication

30/07/2025

CVE-2025-32238 Moyenne · 4,3
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.2 – Authenticated (Subscriber+) Sensitive Information Exposure

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and…

Versions affectées

*-4.5.2

Correctif

4.6.0

Publication

04/04/2025

CVE-2024-54356 Moyenne · 4,3
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 – Cross-Site Request Forgery

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5. This is due to missing or incorrect nonce validation on the vcita_save_settings_callback()…

Versions affectées

*-4.5

Correctif

4.5.2

Publication

11/12/2024

CVE-2024-9872 Moyenne · 5,4
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_user_data_callback() function in all versions up to, and including, 4.5.1.…

Versions affectées

*-4.5.1

Correctif

4.5.2

Publication

05/12/2024

CVE-2024-47638 Moyenne · 6,1
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 – Reflected Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.4.6

Correctif

4.5

Publication

30/09/2024

CVE-2024-35761 Moyenne · 6,4
Online Booking & Scheduling Calendar for WordPress by vcita

vCita Online Booking & Scheduling Calendar <= 4.4.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-4.4.0

Correctif

4.4.1

Publication

17/07/2024

CVE-2024-37499 Élevée · 8,8
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 – Authenticated (Contributor+) Local File Inclusion

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

04/07/2024

CVE-2024-37262 Moyenne · 6,1
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 – Reflected Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

27/06/2024

CVE-2024-5791 Élevée · 7,2
Online Booking & Scheduling Calendar for WordPress by vcita

Appointment Booking and Online Scheduling <= 4.4.2 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and including, 4.4.2 due to missing authorization checks on processAction…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

21/06/2024

CVE-2024-5859 Moyenne · 6,1
Online Booking & Scheduling Calendar for WordPress by vcita

Appointment Booking and Online Scheduling <= 4.4.2 – Reflected Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

20/06/2024

CVE-2023-39992 Moyenne · 6,4
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-4.3.2

Correctif

4.3.3

Publication

10/08/2023

CVE-2023-2416 Moyenne · 5,4
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 – Cross-Site Request Forgery to Account Logout

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.5. This makes…

Versions affectées

*-4.5

Correctif

4.5.2

Publication

02/06/2023

CVE-2023-2414 Moyenne · 5,4
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 – Missing Authorization to Settings Update and Arbitrary File Upload

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This…

Versions affectées

*-4.4.6

Correctif

4.5

Publication

02/06/2023

CVE-2023-2299 Moyenne · 5,3
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 – Missing Authorization on REST-API

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

02/06/2023

CVE-2023-2298 Élevée · 7,2
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 – Unauthenticated Stored Cross-Site Scripting

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping.…

Versions affectées

*-4.3.0

Correctif

4.3.1

Publication

02/06/2023

CVE-2023-2415 Moyenne · 5,4
Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 – Missing Authorization to Account Logout

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This…

Versions affectées

*-4.2.10

Correctif

4.3.0

Publication

02/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités