vCita Online Booking & Scheduling Calendar for WordPress Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-35761) — Medium Severity

A security flaw, identified as CVE-2024-35761, has been found in the vCita Online Booking & Scheduling Calendar for WordPress plugin. This vulnerability is a type of “Cross-site Scripting” (XSS) and specifically, a “Stored XSS” issue. It means that an attacker could inject harmful code into your website through the plugin. This malicious code then gets saved on your site and can run in the web browsers of visitors who access the affected pages, potentially leading to unwanted redirects, advertisements, or other harmful actions.

CVE Details

  • Product: vCita Online Booking & Scheduling Calendar for WordPress by vcita
  • Published Date: June 21, 2024
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts the ‘Online Booking & Scheduling Calendar for WordPress by vcita’ plugin. Specifically, all versions up to and including 4.4.0 are affected.

Current Status

The vulnerability is currently in an ‘Analyzed’ status, meaning it has been investigated and understood.

Severity Level

This vulnerability is rated as ‘Medium’ severity with a CVSS score of 6.5. While considered medium, Patchstack, a vulnerability database, notes it as a ‘Low priority’ issue due to the requirement of user interaction for successful exploitation. This means a privileged user, such as a Contributor, would need to perform a specific action, like clicking a malicious link or visiting a crafted page, for the attack to succeed. However, any XSS can lead to compromised website integrity and user experience.

Possible Solutions

The good news is that a fix is available! To secure your WordPress site, it is crucial to update the ‘Online Booking & Scheduling Calendar for WordPress by vcita’ plugin to version 4.4.1 or later. Updating your plugins promptly is one of the most effective ways to protect your website from known security vulnerabilities. Always ensure you back up your site before performing any updates.

References

  • https://patchstack.com/database/vulnerability/meeting-scheduler-by-vcita/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve
  • https://patchstack.com/database/vulnerability/meeting-scheduler-by-vcita/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.