CVE-2024-54356: WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54356?
CVE-2024-54356 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2024-54356?
To fix CVE-2024-54356, update the vCita Online Booking & Scheduling Calendar for WordPress plugin to version 4.5 or later.
What versions are affected by CVE-2024-54356?
CVE-2024-54356 affects all versions of the vCita Online Booking & Scheduling Calendar for WordPress plugin from n/a up to and including 4.5.
Can CVE-2024-54356 lead to unauthorized actions?
Yes, CVE-2024-54356 may allow attackers to perform unauthorized actions on behalf of users without their consent.
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is a type of attack that tricks the user into executing unwanted actions on a web application where they are authenticated.