SecAlerts
vcita logo

vcita

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 36 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 3, 2023 to present

36
Total CVEs
8
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
45/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
7
Medium
28
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
21
2
CSRF
7
3
Malicious File Upload
1
4
Path Traversal
1

Most Affected Products

1. vcita Online Booking \& Scheduling Calendar Wordpress20
2. vcita Online Booking & Scheduling Calendar for WordPress8
3. vcita Crm And Lead Management By Vcita Wordpress4
4. vcita CRM and Lead Management3
5. vcita Online Payments - Get Paid With Paypal\, Square \& Stripe Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-14433
CVSS 7.2high

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter

8/15/2026🔧 No Patch
CVE-2025-67559
CVSS 5.4medium

WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Broken Access Control vulnerability

12/9/2025🔧 No Patch
CVE-2025-67472
CVSS 8.8high

WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Cross Site Request Forgery (CSRF) vulnerability

12/9/2025🔧 No Patch
CVE-2025-54677
CVSS 9.1critical

WordPress Online Booking & Scheduling Calendar for WordPress by vcita Plugin <= 4.5.3 - Arbitrary File Upload Vulnerability

8/20/2025
CVE-2025-54676
CVSS 6.5medium

WordPress Online Booking & Scheduling Calendar for by vcita Plugin plugin <= 4.5.3 - Cross Site Scripting (XSS) Vulnerability

8/14/2025
CVE-2025-5240
CVSS 6.4medium

CRM and Lead Management by vcita <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter

7/22/2025🔧 No Patch
CVE-2025-32199
CVSS 6.5EPSS 0%medium

WordPress Contact Form Builder by vcita plugin <= 4.10.2 - Cross Site Scripting (XSS) vulnerability

4/10/2025🔧 No Patch
CVE-2025-32238
CVSS 4.3EPSS 0%medium

WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Data Exposure vulnerability

4/4/2025🔧 No Patch
CVE-2024-13702
CVSS 6.4medium

CRM and Lead Management by vcita <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

3/26/2025
CVE-2024-13703
CVSS 4.3medium

CRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Widget Toggle

3/13/2025🔧 No Patch

Monitor vcita in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.