PT-2026-72140 · Vcita · Vcita Online Booking & Scheduling Calendar
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Booking & Scheduling Calendar for WordPress by vcita versions prior to 4.6.1
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. This occurs via the
business id parameter within the REST API endpoint. An attacker can inject arbitrary web scripts into pages that execute automatically when a user accesses the affected page.Recommendations
Update the plugin to a version newer than 4.6.0.
As a temporary mitigation, restrict access to the REST API endpoint utilizing the
business id parameter.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vcita Online Booking & Scheduling Calendar