Vulnerabilities in vCita
30 resultsCVE-2024-11886MEDIUMContact Form and Calls To Action by vcita <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-13703MEDIUMCRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Widget ToggleEPSS 0.3%CVE-2024-9872MEDIUMOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 - Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2024-13717MEDIUMContact Form and Calls To Action by vcita <= 2.7.1 - Missing Authorization to Authenticated (Subscriber+) Contact/Widget ToggleEPSS 0.2%CVE-2024-54356MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2025-67559MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-22661MEDIUMWordPress Online Payments plugin <= 3.20.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-54676MEDIUMWordPress Online Booking & Scheduling Calendar for by vcita Plugin plugin <= 4.5.3 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%CVE-2024-13702MEDIUMCRM and Lead Management by vcita <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2025-67472MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%