Beta

Report

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.2 is vulnerable to Sensitive Data Exposure vulnerability

Subscriber
Published
2025-04-03

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS

Score:4.3

Severity:Medium

Version: 4.5.2

The plugin vendor has not patched this vulnerability at the moment.