vcita Online Booking & Scheduling Calendar Broken Access Control Vulnerability (CVE-2025-67559) — Medium Severity

The “vcita Online Booking & Scheduling Calendar” plugin, a popular tool for managing appointments on WordPress websites, has been found to have a security vulnerability. This flaw, officially identified as CVE-2025-67559, falls under the category of “Broken Access Control.” In simple terms, this means the plugin isn’t properly checking if users have the right permissions to access or perform certain functions. An attacker, even one with low-level privileges like a subscriber on your WordPress site, could potentially exploit this to carry out actions they shouldn’t be authorized to do, compromising the integrity of your booking system or wider website. Understanding and addressing this vulnerability is critical for IT administrators, developers, and anyone managing a WordPress site using this plugin.

CVE Details

This particular issue affects the “Online Booking & Scheduling Calendar for WordPress by vcita” plugin.

  • CVE ID: CVE-2025-67559
  • Published: December 9, 2025
  • Severity: Medium (CVSS: 5.4)
  • Status: Analyzed

This data highlights the official recognition and initial assessment of the vulnerability by the National Vulnerability Database (NVD).

Affected Products

The vulnerability specifically impacts the “Online Booking & Scheduling Calendar for WordPress by vcita” plugin. Any version of this plugin from its initial release up to and including version 4.5.5 is considered vulnerable. If your WordPress site utilizes this plugin within this version range, it is exposed to the potential risks associated with this flaw. Identifying and knowing your plugin versions is the first step towards securing your digital assets.

Current Status

As of December 12, 2025, the vulnerability is in an “Analyzed” status, meaning the details of the flaw are publicly known and understood. While this transparency is vital for the cybersecurity community, it also means that potential attackers have access to this information. Therefore, taking immediate action to mitigate the risk is highly recommended.

Severity Level

CVE-2025-67559 carries a Medium severity rating, with a CVSS score of 5.4. A Medium severity indicates that the vulnerability could lead to some loss of confidentiality, integrity, or availability, but it might require specific conditions or user interaction to be exploited. In this case, the vulnerability allows an authenticated attacker with ‘Subscriber’ privileges to exploit incorrectly configured access control. This could involve manipulating settings or data that only higher-privileged users should be able to touch. While Patchstack also rates this as a “Low priority” issue, it’s always prudent to follow the higher severity rating (Medium) to ensure a robust security posture. A “low priority” assessment from a third-party might factor in the difficulty of exploitation or the perceived impact in typical real-world scenarios, but the underlying risk remains.

Possible Solutions

The most effective and straightforward solution to address this vulnerability is to update your “Online Booking & Scheduling Calendar for WordPress by vcita” plugin. Developers have released a patched version, and upgrading to version 4.6.0 or later will fix the broken access control issue. This update closes the security gap, preventing unauthorized subscriber-level users from exploiting the flaw. Regular updates are the cornerstone of good cybersecurity hygiene, especially for plugins and themes on a content management system like WordPress. Make sure to back up your website before performing any updates. For more insights into securing your WordPress plugins, consider reading our post on [WordPress Plugin Security Best Practices].

References

https://vdp.patchstack.com/database/Wordpress/Plugin/meeting-scheduler-by-vcita/vulnerability/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-5-5-broken-access-control-vulnerability?_s_id=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.