PT-2025-33229 · WordPress · Online Booking & Scheduling Calendar For Wordpress

Que Thanh Tuan - Blue Rock

·

Published

2025-08-14

·

Updated

2025-12-12

·

CVE-2025-54676

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: vcita Online Booking & Scheduling Calendar for WordPress versions through 4.5.3
Description: The software contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') issue that allows Stored XSS.
Recommendations: Update to a version later than 4.5.3.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54676

Affected Products

Online Booking & Scheduling Calendar For Wordpress