The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE ID: CVE-2023-2407
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.1
Vendor: vcita
Product: Event Registration Calendar By vcita
EPSS Score: 0.21% (probability of being exploited)
EPSS Percentile: 58.74% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)