The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction function. This makes it possible for unauthenticated attackers modify the plugin's settings.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-33805 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction function. This makes it possible for unauthenticated attackers modify the plugin's settings.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Vcita online Booking \& Scheduling Calendar
CPEs cpe:2.3:a:vcita:online_booking_\&_scheduling_calendar_for_wordpress:*:*:*:*:*:wordpress:*:* cpe:2.3:a:vcita:online_booking_\&_scheduling_calendar:*:*:*:*:*:wordpress:*:*
Vendors & Products Vcita online Booking \& Scheduling Calendar For Wordpress
Vcita online Booking \& Scheduling Calendar

Sat, 28 Dec 2024 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-12-28T00:58:05.050Z

Reserved: 2023-04-26T12:12:34.510Z

Link: CVE-2023-2299

cve-icon Vulnrichment

Updated: 2024-08-02T06:19:14.652Z

cve-icon NVD

Status : Modified

Published: 2023-06-03T05:15:09.267

Modified: 2025-06-10T12:45:23.150

Link: CVE-2023-2299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.