Stored Cross-Site Scripting Vulnerability in Online Booking & Scheduling Calendar by vcita
CVE-2026-14433
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-14433?
The Online Booking & Scheduling Calendar for WordPress by vcita suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping processes. Specifically, the 'business_id' parameter is exploitable, allowing unauthenticated attackers to inject malicious web scripts. This leads to the execution of these scripts whenever a user interacts with an affected page, potentially compromising user data and overall site integrity.
Affected Version(s)
Online Booking & Scheduling Calendar for WordPress by vcita 0 <= 4.6.0