-Infinity
0

vcita Online Booking & Scheduling Calendar for WordPressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter

Risk 44
Severity
7.2
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Broken Access Control vulnerability

Risk 34
Severity
5.4
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Cross Site Request Forgery (CSRF) vulnerability

Risk 77
Severity
8.8
First published (updated )

vcita Online Booking & Scheduling CalendarWordPress Online Booking & Scheduling Calendar for WordPress by vcita Plugin <= 4.5.3 - Arbitrary File Upload Vulnerability

Risk 66
Severity
9.1
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressWordPress Online Booking & Scheduling Calendar for by vcita Plugin plugin <= 4.5.3 - Cross Site Scripting (XSS) Vulnerability

Risk 34
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vcita CRM and Lead ManagementCRM and Lead Management by vcita <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter

Risk 39
Severity
6.4
First published (updated )

vcita Contact Form Builder by vcitaWordPress Contact Form Builder by vcita plugin <= 4.10.2 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
EPSS
0.03%
First published (updated )

vcita Online Booking & Scheduling CalendarWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Data Exposure vulnerability

Risk 17
Severity
4.3
EPSS
0.03%
First published (updated )

vcita CRM and Lead ManagementCRM and Lead Management by vcita <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

vcita CRM and Lead ManagementCRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Widget Toggle

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vcita Online Payments - Get Paid With Paypal\, Square \& Stripe WordpressOnline Payments – Get Paid with PayPal, Square & Stripe <= 3.20.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

vcita paypal-payment-button-by-vcita (Online Payments – Get Paid with PayPal, Square & Stripe)WordPress Online Payments plugin <= 3.20.0 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
EPSS
0.04%
First published (updated )

vcita Event Registration Calendar By vcitaEvent Registration Calendar By vcita <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5 - Cross Site Request Forgery (CSRF) vulnerability

Risk 35
Severity
5.4
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vcita Contact Form BuilderContact Form Builder <= 4.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via livesite-pay Shortcode

Risk 39
Severity
6.4
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressWordPress Online Booking & Scheduling Calendar for WordPress plugin <= 4.4.6 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 38
Severity
7.1
First published (updated )

vcita Online Booking \& Scheduling Calendar WordpressWordPress Online Booking & Scheduling Calendar plugin <= 4.4.2 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 50
Severity
7.1
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressWordPress Online Booking & Scheduling Calendar for WordPress plugin <= 4.4.2 - Local File Inclusion vulnerability

Risk 38
Severity
6.5
First published (updated )

vcita Online Booking \& Scheduling Calendar WordpressAppointment Booking and Online Scheduling <= 4.4.2 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting

Risk 31
Severity
7.2
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vcita Online Booking \& Scheduling Calendar WordpressWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.4.0 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )

vcita Online Booking \& Scheduling Calendar WordpressAppointment Booking and Online Scheduling <= 4.4.2 - Reflected Cross-Site Scripting

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )

vcita Online Booking \& Scheduling Calendar For Wordpress By Vcita WordpressWordPress Online Booking & Scheduling Calendar for WordPress by vcita Plugin <= 4.3.2 is vulnerable to Cross Site Scripting (XSS)

Risk 50
Severity
7.1
First published (updated )

vcita Online Booking \& Scheduling Calendar WordpressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Missing Authorization to Settings Update and Arbitrary File Upload

Risk 34
Severity
5.4
First published (updated )

vcita Crm And Lead Management By Vcita WordpressCRM and Lead Management by vcita <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 40
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vcita Online Booking \& Scheduling Calendar For Wordpress By Vcita WordpressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout

Risk 38
Severity
6.5
First published (updated )

vcita Contact Form Builder By Vcita WordpressContact Form Builder by vcita <= 4.10.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Risk 38
Severity
6.1
First published (updated )

vcita Online Booking \& Scheduling Calendar For Wordpress WordpressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site Scripting

Risk 44
Severity
7.2
First published (updated )

vcita Online Booking \& Scheduling Calendar For Wordpress By Vcita WordpressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout

Risk 35
Severity
5.4
First published (updated )

vcita Online Booking \& Scheduling Calendar For Wordpress WordpressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203