PT-2023-19438 · Vcita · Online Booking & Scheduling Calendar For Wordpress

·

CVE-2023-2415

·

Published

2023-06-03

·

Updated

2025-06-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress versions up to, and including, 4.2.10
Description The issue is related to a missing capability check on the vcita logout callback function, allowing authenticated attackers with minimal permissions to modify data. This can lead to a denial of service on the appointment scheduler by logging out a connected account. The attackers can have minimal permissions, such as a subscriber.
Recommendations For versions up to, and including, 4.2.10, update to a version higher than 4.2.10 to resolve the issue. As a temporary workaround, consider disabling the vcita logout callback function until a patch is available. Restrict access to the appointment scheduler to minimize the risk of exploitation.

Exploit

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-2415

Affected Products

Online Booking & Scheduling Calendar For Wordpress