June 3, 2023, 5:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for unauthenticated to logout a vctia connected account which would cause a denial of service on the appointment scheduler, via a forged request granted they can trick a site user into performing an action such as clicking on a link.

account amp booking calendar check cross-site cross-site request forgery cve denial of service forgery function logout missing nonce plugin request service vulnerable wordpress

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Cyber Crime Student Internship

@ West Midlands Police | Birmingham, West Midlands, United Kingdom

Cyber Security Engineer (Junior/Journeyman)

@ CSEngineering | El Segundo, CA 90245, USA

Application Security Lead

@ Tokio Marine HCC | United Kingdom