Vulnerabilities > Vcita > Online Booking Scheduling Calendar > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-06-09 CVE-2023-2414 Missing Authorization vulnerability in Vcita Online Booking & Scheduling Calendar
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6.
network
low complexity
vcita CWE-862
4.3