plugin

Meeting Scheduler By Vcita Vulnerabilities

39 known security issues reported for the Meeting Scheduler By Vcita WordPress plugin. Most recent disclosed Aug 14, 2026.

5 high 15 medium

Running Meeting Scheduler By Vcita on your site? Check whether your installed version is affected.

Scan your site free

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter

high

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

CVSS:
7.2
Affected:
up to 4.6.0
Fix:
No patched version reported
Disclosed:
Aug 14, 2026

CVE-2026-14433 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] <= 4.5.5 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.

Affected:
up to 4.5.5
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67472 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] <= 4.5.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.

Affected:
up to 4.5.5
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67559 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 - Cross-Site Request Forgery

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorize...

CVSS:
4.3
Affected:
up to 4.5.5
Fixed in:
4.6.0
Disclosed:
Nov 12, 2025

CVE-2025-67472 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 - Missing Authorization

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an...

CVSS:
4.3
Affected:
up to 4.5.5
Fixed in:
4.6.0
Disclosed:
Nov 12, 2025

CVE-2025-67559 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5.5

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Using Malicious Files. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.3.

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Aug 20, 2025

CVE-2025-54677 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 - Authenticated (Author+) Arbitrary File Upload

high

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files...

CVSS:
8.8
Affected:
up to 4.5.3
Fixed in:
4.5.5
Disclosed:
Aug 14, 2025

CVE-2025-54677 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Stored XSS. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.3.

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Aug 14, 2025

CVE-2025-54676 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...

CVSS:
6.4
Affected:
up to 4.5.3
Fixed in:
4.5.5
Disclosed:
Jul 30, 2025

CVE-2025-54676 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.2 - Authenticated (Subscriber+) Sensitive Information Exposure

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 4.5.2
Fixed in:
4.6.0
Disclosed:
Apr 4, 2025

CVE-2025-32238 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] <= 4.5.2 (unfixed)

unknown

[en] Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Retrieve Embedded Sensitive Data. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.2.

Affected:
up to 4.5.2
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32238 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in vCita.com Online Booking & Scheduling Calendar for WordPress by vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.

Affected:
up to 4.5.2
Fixed in:
4.5.2
Disclosed:
Dec 16, 2024

CVE-2024-54356 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5. This is due to missing or incorrect nonce validation on the vcita_save_settings_callback() function. This makes it possible for unauthenticated attacker...

CVSS:
4.3
Affected:
up to 4.5
Fixed in:
4.5.2
Disclosed:
Dec 11, 2024

CVE-2024-54356 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5.2

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_user_data_callback() function in all versions up to, and including, 4.5.1. This makes it possible for authenticated attackers,...

Affected:
up to 4.5.2
Fixed in:
4.5.2
Disclosed:
Dec 6, 2024

CVE-2024-9872 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_user_data_callback() function in all versions up to, and including, 4.5.1. This makes it possible for authenticated attackers, with...

CVSS:
5.4
Affected:
up to 4.5.1
Fixed in:
4.5.2
Disclosed:
Dec 5, 2024

CVE-2024-9872 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.6.

Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Oct 5, 2024

CVE-2024-47638 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Reflected Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 4.4.6
Fixed in:
4.5
Disclosed:
Sep 30, 2024

CVE-2024-47638 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.4.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2.

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Jul 22, 2024

CVE-2024-37262 on NVD →

vCita Online Booking & Scheduling Calendar <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 4.4.0
Fixed in:
4.4.1
Disclosed:
Jul 17, 2024

CVE-2024-35761 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.4.3

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Path Traversal.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2.

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Jul 9, 2024

CVE-2024-37499 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Authenticated (Contributor+) Local File Inclusion

high

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allow...

CVSS:
8.8
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jul 4, 2024

CVE-2024-37499 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Reflected Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jun 27, 2024

CVE-2024-37262 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.4.3

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and including, 4.4.2 due to missing authorization checks on processAction function, as well as insufficient input sanitization and outpu...

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Jun 22, 2024

CVE-2024-5791 on NVD →

Appointment Booking and Online Scheduling <= 4.4.2 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting

high

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and including, 4.4.2 due to missing authorization checks on processAction function, as well as insufficient input sanitization and output esc...

CVSS:
7.2
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jun 21, 2024

CVE-2024-5791 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.4.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.0.

Affected:
up to 4.4.1
Fixed in:
4.4.1
Disclosed:
Jun 21, 2024

CVE-2024-35761 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.4.3

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Jun 21, 2024

CVE-2024-5859 on NVD →

Appointment Booking and Online Scheduling <= 4.4.2 - Reflected Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...

CVSS:
6.1
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jun 20, 2024

CVE-2024-5859 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.3.3

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.

Affected:
up to 4.3.3
Fixed in:
4.3.3
Disclosed:
Sep 4, 2023

CVE-2023-39992 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

CVSS:
6.4
Affected:
up to 4.3.2
Fixed in:
4.3.3
Disclosed:
Aug 10, 2023

CVE-2023-39992 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with min...

Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Jun 9, 2023

CVE-2023-2414 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.3.1

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
Jun 3, 2023

CVE-2023-2298 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.3.0

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal p...

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jun 3, 2023

CVE-2023-2415 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.5.2

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for unauthenticated to logout a vctia connected accoun...

Affected:
up to 4.5.2
Fixed in:
4.5.2
Disclosed:
Jun 3, 2023

CVE-2023-2416 on NVD →

Online Booking &amp; Scheduling Calendar for WordPress by vcita [meeting-scheduler-by-vcita] < 4.4.3

unknown

[en] The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction function. This mak...

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Jun 3, 2023

CVE-2023-2299 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site Scripting

high

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...

CVSS:
7.2
Affected:
up to 4.3.0
Fixed in:
4.3.1
Disclosed:
Jun 2, 2023

CVE-2023-2298 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.5. This makes it possible for unauthenticated to logout a vctia connected account which...

CVSS:
5.4
Affected:
up to 4.5
Fixed in:
4.5.2
Disclosed:
Jun 2, 2023

CVE-2023-2416 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permis...

CVSS:
5.4
Affected:
up to 4.2.10
Fixed in:
4.3.0
Disclosed:
Jun 2, 2023

CVE-2023-2415 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Missing Authorization to Settings Update and Arbitrary File Upload

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal...

CVSS:
5.4
Affected:
up to 4.4.6
Fixed in:
4.5
Disclosed:
Jun 2, 2023

CVE-2023-2414 on NVD →

Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API

medium

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check on the processAction function. This makes it...

CVSS:
5.3
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jun 2, 2023

CVE-2023-2299 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database