CVE-2026-14433: Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'businessid' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14433?
CVE-2026-14433 has a high severity rating of 7.2.
What type of vulnerability is CVE-2026-14433?
CVE-2026-14433 is a Stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2026-14433?
To fix CVE-2026-14433, upgrade the vcita Online Booking & Scheduling Calendar for WordPress plugin to version 4.6.1 or later.
Who is affected by CVE-2026-14433?
All users of the vcita Online Booking & Scheduling Calendar for WordPress plugin version 4.6.0 or earlier are affected by CVE-2026-14433.
What could an attacker do exploiting CVE-2026-14433?
An attacker exploiting CVE-2026-14433 could execute arbitrary scripts in the context of users interacting with the affected application.