Cross-Site Request Forgery Vulnerability in vcita Online Booking & Scheduling Calendar Plugin for WordPress
CVE-2025-67472
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-67472?
A Cross-Site Request Forgery (CSRF) vulnerability present in the vcita Online Booking & Scheduling Calendar for WordPress allows attackers to perform unauthorized actions on behalf of users. If exploited, this could potentially lead to unauthorized access or modifications to user data without their consent. This vulnerability affects versions of the plugin up to 4.5.5, and it is crucial for site owners to implement measures to safeguard their applications against such security threats.
Affected Version(s)
Online Booking & Scheduling Calendar for WordPress by vcita <= n/a