{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-booking--scheduling-calendar-for-wordpress-by-vcita/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-14433"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Booking \u0026 Scheduling Calendar for WordPress by vcita"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["vcita"],"content_html":"\u003cp\u003eThe 'Online Booking \u0026amp; Scheduling Calendar for WordPress by vcita' plugin is vulnerable to stored cross-site scripting (XSS) in all versions up to and including 4.6.0 (CVE-2026-14433). The vulnerability arises from insufficient input sanitization and output escaping on the 'business_id' parameter. This flaw allows an unauthenticated attacker to inject malicious JavaScript into the application, which is then stored and subsequently executed in the browser of any user who views the page where the injected content is rendered. Given the plugin's role in booking and scheduling, this could be leveraged for session hijacking, unauthorized actions on behalf of site administrators, or redirecting site visitors to malicious domains.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an instance of the 'Online Booking \u0026amp; Scheduling Calendar for WordPress by vcita' plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request containing a malicious JavaScript payload within the 'business_id' parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to sanitize the 'business_id' input before processing or storing it.\u003c/li\u003e\n\u003cli\u003eThe malicious payload is saved into the WordPress database.\u003c/li\u003e\n\u003cli\u003eA victim user (e.g., administrator or site customer) navigates to the compromised web page.\u003c/li\u003e\n\u003cli\u003eThe web server renders the stored, unsanitized payload into the HTML response.\u003c/li\u003e\n\u003cli\u003eThe victim's browser executes the injected JavaScript script in the context of the vulnerable site.\u003c/li\u003e\n\u003cli\u003eAttacker achieves execution of arbitrary code within the victim's browser session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14433 can lead to the compromise of user sessions, allowing attackers to perform unauthorized actions as the victim. If an administrator is targeted, this could lead to full site compromise, including the modification of site content, exfiltration of sensitive booking data, or redirection of traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Online Booking \u0026amp; Scheduling Calendar for WordPress by vcita' plugin to the latest version available (patch versions beyond 4.6.0).\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) to mitigate the impact of XSS attacks by restricting the execution of inline scripts and unauthorized external resources.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for HTTP requests containing abnormal character strings (e.g., '\u0026lt;script\u0026gt;', 'javascript:', 'onerror=') within parameter values.\u003c/li\u003e\n\u003cli\u003eUtilize a Web Application Firewall (WAF) to inspect and block malicious payloads targeting the 'business_id' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T04:16:32Z","date_published":"2026-08-15T04:16:32Z","id":"https://feed.craftedsignal.io/briefs/2026-08-vcita-xss/","summary":"A stored cross-site scripting (XSS) vulnerability in the vcita WordPress plugin up to version 4.6.0 allows unauthenticated attackers to inject arbitrary scripts via the 'business_id' parameter.","title":"Stored XSS in Online Booking \u0026 Scheduling Calendar for WordPress by vcita","url":"https://feed.craftedsignal.io/briefs/2026-08-vcita-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Booking \u0026 Scheduling Calendar for WordPress by Vcita","version":"https://jsonfeed.org/version/1.1"}