First published: Sat Jun 03 2023(Updated: )
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for unauthenticated to logout a vctia connected account which would cause a denial of service on the appointment scheduler, via a forged request granted they can trick a site user into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vcita Online Booking & Scheduling Calendar | <=4.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2416 is a vulnerability in the Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress that allows for Cross-Site Request Forgery attacks.
The severity of CVE-2023-2416 is medium, with a severity value of 6.5.
CVE-2023-2416 affects versions up to and including 4.2.10 of the Online Booking & Scheduling Calendar for WordPress by vcita plugin, allowing unauthenticated users to perform logout actions.
To fix CVE-2023-2416, update the Online Booking & Scheduling Calendar for WordPress by vcita plugin to a version beyond 4.2.10.
You can find more information about CVE-2023-2416 at the following references: [link1], [link2], [link3].