Online Booking & Scheduling Calendar for WordPress by vcita

Online Booking & Scheduling Calendar for WordPress by vcita has 20 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 19 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 5 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 10 of the records (50%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

19 of the records (95%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

13 independent researchers contributed these findings, most of them (5) reported by Jonas Höbenreich.

01234567891002.06.2023Today02.06.20235.4Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout CVSS 5.4 · 02.06.20237.2Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 02.06.20235.4Online Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout CVSS 5.4 · 02.06.20235.3Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API CVSS 5.3 · 02.06.20235.4Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Missing Authorization to Settings Update and Arbitrary File Upload CVSS 5.4 · 02.06.202310.08.20236.4Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 10.08.202320.06.20246.1Appointment Booking and Online Scheduling <= 4.4.2 - Reflected Cross-Site Scripting CVSS 6.1 · 20.06.202421.06.20247.2Appointment Booking and Online Scheduling <= 4.4.2 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 21.06.202427.06.20246.1Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Reflected Cross-Site Scripting CVSS 6.1 · 27.06.202404.07.20248.8Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 04.07.202417.07.20246.4vCita Online Booking & Scheduling Calendar <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.07.202430.09.20246.1Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Reflected Cross-Site Scripting CVSS 6.1 · 30.09.202405.12.20245.4Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 5.4 · 05.12.202411.12.20244.3Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery CVSS 4.3 · 11.12.202404.04.20254.3Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.2 - Authenticated (Subscriber+) Sensitive Information Exposure CVSS 4.3 · 04.04.202530.07.20256.4Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 30.07.202514.08.20258.8Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 - Authenticated (Author+) Arbitrary File Upload CVSS 8.8 · 14.08.202512.11.20254.3Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 - Cross-Site Request Forgery CVSS 4.3 · 12.11.20254.3Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 - Missing Authorization CVSS 4.3 · 12.11.202514.08.20267.2Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter CVSS 7.2 · 14.08.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage95%
Open

1

Fixed

19

Get automatic notifications for all Online Booking & Scheduling Calendar for WordPress by vcita vulnerabilities before they are exploited.

Most severe open issueCVSS 7.2CVE-2026-14433

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter

Read the full analysis

Vulnerability Records

20 records
2026-08-14 14:02CVE-2026-14433
7.2
High
MatilJNo
2025-11-12 00:00CVE-2025-67472
4.3
Medium
Kévin Mosbahi (Mika)Yes
2025-11-12 00:00CVE-2025-67559
4.3
Medium
Kévin Mosbahi (Mika)Yes
2025-08-14 00:00CVE-2025-54677
8.8
High
Que Thanh Tuan - Blue RockYes
2025-07-30 00:00CVE-2025-54676
6.4
Medium
Que Thanh Tuan - Blue RockYes
2025-04-04 00:00CVE-2025-32238
4.3
Medium
Joshua ChanYes
2024-12-11 00:00CVE-2024-54356
4.3
Medium
Marek MikitaYes
2024-12-05 00:00CVE-2024-9872
5.4
Medium
stealthcopterYes
2024-09-30 00:00CVE-2024-47638
6.1
Medium
Abdi PranataYes
2024-07-17 00:00CVE-2024-35761
6.4
Medium
Ngô Thiên An (ancorn_)Yes
Showing 1–10 of 20 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C