Description
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
Published: 2026-09-23
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw in the WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin versions up to 4.6.0. Attackers who do not possess valid credentials can bypass normal access restrictions and reach privileged administrative endpoints. This flaw can allow the attacker to view, modify, or delete booking data and potentially perform other privileged operations normally reserved for site administrators. The weakness falls under the Unrestricted Access to a Sensitive Resource category (CWE-862).

Affected Systems

The affected product is the WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin, with all releases equal to or earlier than version 4.6.0. The vulnerability is reported for all installation environments running one of the affected versions on a WordPress site.

Risk and Exploitability

The flaw carries a CVSS score of 7.5, indicating significant impact if exploited. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, suggesting that publicly known exploit code may not yet exist. Exploitation is likely possible through the plugin's exposed web interfaces without authentication, giving an unauthenticated attacker the ability to access privileged functions. Because access is unauthenticated, a widespread attack vector is the publicly accessible WordPress admin URLs that the plugin injects.

Generated by OpenCVE AI on September 23, 2026 at 20:07 UTC.

Remediation

Vendor Solution

Update the WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin to the latest available version (at least 4.6.3).


OpenCVE Recommended Actions

  • Update the WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin to the latest version available, at least 4.6.3, to remove the broken access control bug.
  • If an immediate update is not feasible, disable the plugin’s administrative features or the entire plugin until the patch is applied to prevent unauthenticated access to privileged endpoints.
  • Review all user accounts on the WordPress site to ensure that only trusted administrators have access to the plugin’s configuration and scheduling pages.
  • Monitor the web server logs for any attempts to access the plugin’s admin URLs, and block or alert on repeated unauthenticated access attempts.

Generated by OpenCVE AI on September 23, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Vcita
Vcita online Booking & Scheduling Calendar For Wordpress By Vcita
Wordpress
Wordpress wordpress
Vendors & Products Vcita
Vcita online Booking & Scheduling Calendar For Wordpress By Vcita
Wordpress
Wordpress wordpress

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
Title WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.6.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Vcita Online Booking & Scheduling Calendar For Wordpress By Vcita
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T19:42:44.139Z

Reserved: 2026-09-22T08:30:28.073Z

Link: CVE-2026-95513

cve-icon Vulnrichment

Updated: 2026-09-23T19:06:11.497Z

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:50.933

Modified: 2026-09-23T20:17:24.483

Link: CVE-2026-95513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T22:30:10Z

Weaknesses