Impact
Cross‑Site Request Forgery (CSRF) is a weakness identified in the vcita Online Booking & Scheduling Calendar plugin for WordPress, classified as CWE-352: Cross‑Site Request Forgery. The flaw permits an attacker to send forged requests that may trigger state‑changing actions the authenticated user is authorized to execute.
Affected Systems
The affected product is vcita's Online Booking & Scheduling Calendar for WordPress by vcita. All releases up to and including version 4.5.5 are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk. The EPSS score of < 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote via a web request that forces an authenticated WordPress session to execute a forged action. The flaw does not require direct credentials, but it relies on the victim’s authenticated session.
OpenCVE Enrichment