CVE-2023-2416: Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcitalogoutcallback function in versions up to, and including, 4.2.10. This makes it possible for unauthenticated to logout a vctia connected account which would cause a denial of service on the appointment scheduler, via a forged request granted they can trick a site user into performing an action such as clicking on a link.
Other sources
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcitalogoutcallback function in versions up to, and including, 4.5. This makes it possible for unauthenticated to logout a vctia connected account which would cause a denial of service on the appointment scheduler, via a forged request granted they can trick a site user into performing an action such as clicking on a link.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2416?
CVE-2023-2416 is a vulnerability in the Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress that allows for Cross-Site Request Forgery attacks.
What is the severity of CVE-2023-2416?
The severity of CVE-2023-2416 is medium, with a severity value of 6.5.
How does CVE-2023-2416 affect the Online Booking & Scheduling Calendar for WordPress by vcita plugin?
CVE-2023-2416 affects versions up to and including 4.2.10 of the Online Booking & Scheduling Calendar for WordPress by vcita plugin, allowing unauthenticated users to perform logout actions.
How can I fix CVE-2023-2416?
To fix CVE-2023-2416, update the Online Booking & Scheduling Calendar for WordPress by vcita plugin to a version beyond 4.2.10.
Where can I find more information about CVE-2023-2416?
You can find more information about CVE-2023-2416 at the following references: [link1], [link2], [link3].