Understanding the Critical Threat
A serious security flaw, identified as an Unrestricted Upload of File with Dangerous Type vulnerability, has been discovered in the vcita Online Booking & Scheduling Calendar for WordPress plugin. This critical vulnerability allows attackers to upload malicious files onto your website. If exploited, this could lead to a complete takeover of your WordPress site, unauthorized data access, or other severe compromises, posing a significant risk to your website’s integrity and your users’ data.
CVE Details
- Product: vcita Online Booking & Scheduling Calendar for WordPress
- Published: August 20, 2025
- Severity: CRITICAL
- Status: Analyzed
Affected Products
This vulnerability impacts the vcita Online Booking & Scheduling Calendar for WordPress plugin. Specifically, all versions from its inception up to and including 4.5.3 are at risk. If you are running any of these versions, your website is potentially exposed to this critical threat.
Current Status
The vulnerability has been thoroughly analyzed, and its critical nature has been confirmed. A fix has been released by vcita to address this security gap. Users are strongly advised to take immediate action to protect their websites.
Severity Level
With a CVSS score of 9.1, this vulnerability is rated as CRITICAL. This rating indicates a high potential for severe impact, meaning an attacker could gain extensive control over your website with relatively low effort. The ability to upload any type of file, including executable scripts, means that an attacker could install backdoors, deface your site, or even compromise your server.
Possible Solutions
Protecting your WordPress site from this critical vulnerability is paramount. The good news is that a fix is available:
- Update Immediately: The most crucial step is to update your vcita Online Booking & Scheduling Calendar for WordPress plugin to version 4.5.5 or later. This updated version contains the necessary patches to close the arbitrary file upload loophole.
- Consider Mitigation: While updating is the definitive solution, some security services, like Patchstack, offer temporary mitigation rules to block attacks against vulnerable versions until you can perform the update. This can provide a crucial layer of immediate protection.
Always ensure your WordPress core, themes, and all other plugins are kept up-to-date to maintain a strong security posture. Regularly back up your website to ensure you can recover quickly in case of an incident.
References
https://patchstack.com/database/wordpress/plugin/meeting-scheduler-by-vcita/vulnerability/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-5-3-arbitrary-file-upload-vulnerability?_s_id=cve


