Vulnerabilities > CVE-2023-2299 - Missing Authorization vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress 4.2.10

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
vcita
CWE-862

Summary

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction function. This makes it possible for unauthenticated attackers modify the plugin's settings.

Vulnerable Configurations

Part Description Count
Application
Vcita
1

Common Weakness Enumeration (CWE)