CVE-2024-54356 MEDIUM

CVE-2024-54356: WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5 - Cross Site Request Forgery (CSRF) vulnerability

Vendor Vcita
Product Online Booking & Scheduling Calendar for WordPress by vcita
Weakness CWE-352 · CSRF
Published December 16, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.

Explanation of Vulnerability in Simple Terms

02Summary

The vcita Online Booking & Scheduling Calendar plugin for WordPress versions 4.5 and earlier is vulnerable to cross-site request forgery (CSRF). An attacker can trick a logged-in site administrator into performing unwanted actions—such as modifying plugin settings or creating bookings—by sending them a malicious link or embedding code on a webpage. The plugin does not properly validate requests to ensure they originate from the site itself.

What an attacker can do

03Attacker Capabilities

Trick an admin into modifying plugin settings or creating unwanted bookings via a malicious link.

Potential impact on your site

04Site Impact

An attacker can alter your booking calendar settings or create fake bookings without your knowledge.

Conditions required to exploit

05Prerequisites

Admin must be logged in and click a malicious link or visit an attacker-controlled page.

Key dates

06Disclosure timeline

December 16, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE