Cross-Site Request Forgery Vulnerability in vcita Online Booking & Scheduling Calendar Plugin for WordPress
CVE-2025-67472

8.8HIGH

What is CVE-2025-67472?

A Cross-Site Request Forgery (CSRF) vulnerability present in the vcita Online Booking & Scheduling Calendar for WordPress allows attackers to perform unauthorized actions on behalf of users. If exploited, this could potentially lead to unauthorized access or modifications to user data without their consent. This vulnerability affects versions of the plugin up to 4.5.5, and it is crucial for site owners to implement measures to safeguard their applications against such security threats.

Affected Version(s)

Online Booking & Scheduling Calendar for WordPress by vcita <= n/a

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika | Patchstack Bug Bounty Program
.