Vulnerabilities > Vcita > Online Booking Scheduling Calendar FOR Wordpress BY Vcita > 4.1.5

DATE CVE VULNERABILITY TITLE RISK
2023-09-04 CVE-2023-39992 Cross-site Scripting vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita
Unauth.
network
low complexity
vcita CWE-79
6.1
2023-06-03 CVE-2023-2415 Missing Authorization vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10.
network
low complexity
vcita CWE-862
5.4
2023-06-03 CVE-2023-2416 Cross-Site Request Forgery (CSRF) vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10.
network
low complexity
vcita CWE-352
6.5