CVE-2025-54676: WordPress Online Booking & Scheduling Calendar for by vcita Plugin plugin <= 4.5.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54676?
CVE-2025-54676 has been classified as a high severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2025-54676?
To fix CVE-2025-54676, update the vcita Online Booking & Scheduling Calendar plugin for WordPress to the latest version beyond 4.5.3.
What software is affected by CVE-2025-54676?
CVE-2025-54676 affects vcita Online Booking & Scheduling Calendar for WordPress versions up to and including 4.5.3.
What type of vulnerability is CVE-2025-54676?
CVE-2025-54676 is an improper neutralization of input during web page generation vulnerability, commonly known as cross-site scripting (XSS).
Can CVE-2025-54676 lead to data breaches?
Yes, CVE-2025-54676 can lead to data breaches as it allows attackers to inject malicious scripts into web pages viewed by other users.