The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.
CVE ID: CVE-2023-2415
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.4
Vendor: vcita
Product: Online Booking & Scheduling Calendar for WordPress by vcita
EPSS Score: 0.1% (probability of being exploited)
EPSS Percentile: 43.31% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)