A security flaw, identified as CVE-2024-35761, has been found in the vCita Online Booking & Scheduling Calendar for WordPress plugin. This vulnerability is a type of “Cross-site Scripting” (XSS) and specifically, a “Stored XSS” issue. It means that an attacker could inject harmful code into your website through the plugin. This malicious code then gets saved on your site and can run in the web browsers of visitors who access the affected pages, potentially leading to unwanted redirects, advertisements, or other harmful actions.
CVE Details
- Product: vCita Online Booking & Scheduling Calendar for WordPress by vcita
- Published Date: June 21, 2024
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts the ‘Online Booking & Scheduling Calendar for WordPress by vcita’ plugin. Specifically, all versions up to and including 4.4.0 are affected.
Current Status
The vulnerability is currently in an ‘Analyzed’ status, meaning it has been investigated and understood.
Severity Level
This vulnerability is rated as ‘Medium’ severity with a CVSS score of 6.5. While considered medium, Patchstack, a vulnerability database, notes it as a ‘Low priority’ issue due to the requirement of user interaction for successful exploitation. This means a privileged user, such as a Contributor, would need to perform a specific action, like clicking a malicious link or visiting a crafted page, for the attack to succeed. However, any XSS can lead to compromised website integrity and user experience.
Possible Solutions
The good news is that a fix is available! To secure your WordPress site, it is crucial to update the ‘Online Booking & Scheduling Calendar for WordPress by vcita’ plugin to version 4.4.1 or later. Updating your plugins promptly is one of the most effective ways to protect your website from known security vulnerabilities. Always ensure you back up your site before performing any updates.
References
- https://patchstack.com/database/vulnerability/meeting-scheduler-by-vcita/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve
- https://patchstack.com/database/vulnerability/meeting-scheduler-by-vcita/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve


