CVE-2025-67472: WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67472?
CVE-2025-67472 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-67472?
To fix CVE-2025-67472, update vcita Online Booking & Scheduling Calendar for WordPress to the latest version above 4.5.5.
What versions are affected by CVE-2025-67472?
CVE-2025-67472 affects versions of vcita Online Booking & Scheduling Calendar for WordPress from n/a up to and including 4.5.5.
What are the potential risks of CVE-2025-67472?
The risks of CVE-2025-67472 include unauthorized actions performed on behalf of users without their consent.
Who is impacted by CVE-2025-67472?
Users of the vcita Online Booking & Scheduling Calendar for WordPress up to version 4.5.5 are impacted by CVE-2025-67472.