Understanding the CSRF Vulnerability in vcita Online Booking & Scheduling Calendar
A significant security flaw has been identified in the vcita Online Booking & Scheduling Calendar for WordPress plugin. This vulnerability, known as Cross-Site Request Forgery (CSRF), could allow attackers to trick authenticated users into performing actions they didn’t intend. Imagine being logged into your WordPress site as an administrator; a malicious actor could craft a special link or embed code on another website. If you were to visit that malicious site, the hidden code could force your browser to send a request to your WordPress site, executing an action using your active session. This means an attacker could potentially make changes to your website without your direct consent or knowledge, simply by exploiting your active login.
CVE Details
- Product: vcita Online Booking & Scheduling Calendar for WordPress (plugin name: meeting-scheduler-by-vcita)
- Published: December 9, 2025
- Severity: High (CVSS Score 8.8)
- Status: Analyzed
Affected Products
The Cross-Site Request Forgery (CSRF) vulnerability impacts versions of the “Online Booking & Scheduling Calendar for WordPress by vcita” plugin up to and including version 4.5.5. If you are using this plugin on your WordPress website and it’s running an older version, your site is at risk.
Current Status
This vulnerability has been officially “Analyzed,” meaning its details have been investigated and confirmed by security researchers. However, being “Analyzed” does not mean the threat is gone; it simply indicates that the issue is understood. Users must take action to protect their installations.
Severity Level
This vulnerability carries a High severity rating with a CVSS score of 8.8. While the Patchstack report indicated a lower CVSS score of 4.3 and a “Low priority”, the official CVE data assigns a High severity. A CSRF vulnerability can be critical as it bypasses standard security checks by leveraging a user’s existing authentication. In the context of a WordPress plugin that handles bookings and scheduling, this could lead to unauthorized actions, data manipulation, or even compromise of site integrity if a high-privileged user is targeted.
Possible Solutions
To secure your WordPress website against this CSRF vulnerability, it is crucial to update the vcita Online Booking & Scheduling Calendar for WordPress plugin immediately. The issue has been addressed in version 4.6.0. Therefore, the recommended solution is to update your plugin to version 4.6.0 or any subsequent version that becomes available. Always ensure you back up your website before performing any updates.
References
https://vdp.patchstack.com/database/Wordpress/Plugin/meeting-scheduler-by-vcita/vulnerability/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-5-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve


