CVE-2024-9872: Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcitasaveuserdatacallback() function in all versions up to, and including, 4.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject malicious web scripts and update settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9872?
CVE-2024-9872 is classified as a medium severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-9872?
To fix CVE-2024-9872, update the Online Booking & Scheduling Calendar for WordPress plugin to version 4.5.2 or later.
What versions are affected by CVE-2024-9872?
CVE-2024-9872 affects all versions of the Online Booking & Scheduling Calendar for WordPress plugin up to and including version 4.5.1.
Who is the vendor for CVE-2024-9872?
The vendor for CVE-2024-9872 is vcita, the company behind the Online Booking & Scheduling Calendar for WordPress plugin.
What type of vulnerability is CVE-2024-9872?
CVE-2024-9872 is an authorization issue that allows unauthorized modification of user data.