
Online Booking & Scheduling Calendar for WordPress by vcita Security & Risk Analysis
wordpress.org/plugins/meeting-scheduler-by-vcitaLet clients schedule meetings with you online! No more back & forth emails
Is Online Booking & Scheduling Calendar for WordPress by vcita Safe to Use in 2026?
Generally Safe
Score 88/100Online Booking & Scheduling Calendar for WordPress by vcita has a strong security track record. Known vulnerabilities have been patched promptly.
The 'meeting-scheduler-by-vcita' plugin version 4.6.0 presents a mixed security posture. While it demonstrates strengths such as 100% SQL query sanitization via prepared statements and a good number of nonce and capability checks, several significant concerns emerge. The presence of one unprotected REST API route, coupled with a notable 22% of output escaping, suggests potential vulnerabilities. The taint analysis, while limited, did reveal one flow with unsanitized paths, which, although not critical or high severity in this analysis, warrants attention given the plugin's history.
Key Concerns
- 1 unprotected REST API route
- 22% of outputs properly escaped
- 1 flow with unsanitized paths
- 19 known CVEs historically
- 4 high severity historical CVEs
- 15 medium severity historical CVEs
Online Booking & Scheduling Calendar for WordPress by vcita Security Vulnerabilities
CVEs by Year
Severity Breakdown
19 total CVEs
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 - Cross-Site Request Forgery
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.5 - Missing Authorization
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 - Authenticated (Author+) Arbitrary File Upload
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.2 - Authenticated (Subscriber+) Sensitive Information Exposure
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Reflected Cross-Site Scripting
vCita Online Booking & Scheduling Calendar <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Authenticated (Contributor+) Local File Inclusion
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Reflected Cross-Site Scripting
Appointment Booking and Online Scheduling <= 4.4.2 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting
Appointment Booking and Online Scheduling <= 4.4.2 - Reflected Cross-Site Scripting
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.6 - Missing Authorization to Settings Update and Arbitrary File Upload
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site Scripting
Online Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout
Online Booking & Scheduling Calendar for WordPress by vcita Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Online Booking & Scheduling Calendar for WordPress by vcita Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 11
Maintenance & Trust
Online Booking & Scheduling Calendar for WordPress by vcita Maintenance & Trust
Maintenance Signals
Community Trust
Online Booking & Scheduling Calendar for WordPress by vcita Alternatives
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
SuperSaaS – online appointment scheduling
supersaas-appointment-scheduling
SuperSaaS is a flexible appointment scheduling system that works with many different businesses. The basic version is free.
Cal24h
cal24h
Embed the Cal24h booking experience in WordPress with a shortcode, Gutenberg block, or floating modal.
EHx Events
ehx-events
A powerful event booking and management system for WordPress websites.
NiftyBukzee – Calendar Booking Plugin for Appointments and Events
niftybukzee
Gain More customers with Quick and Easy 3-step appointment booking with service providers: Calendar, Payments, Google Meet & more.
Online Booking & Scheduling Calendar for WordPress by vcita Developer Profile
3 plugins · 1K total installs
How We Detect Online Booking & Scheduling Calendar for WordPress by vcita
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meeting-scheduler-by-vcita/assets/js/pc_v.js/wp-content/plugins/meeting-scheduler-by-vcita/assets/js/utils_v.js/wp-content/plugins/meeting-scheduler-by-vcita/assets/js/mixpanel_v.js/wp-content/plugins/meeting-scheduler-by-vcita/assets/style/style_v.cssmeeting-scheduler-by-vcita/assets/js/pc_v.js?ver=meeting-scheduler-by-vcita/assets/js/utils_v.js?ver=meeting-scheduler-by-vcita/assets/js/mixpanel_v.js?ver=meeting-scheduler-by-vcita/assets/style/style_v.css?ver=HTML / DOM Fingerprints
wpschd_admin_noticewpschd_admin_notice-imagewpschd_admin_notice-textvcita__btn__bluewpschd_admin_notice_closeCheck if vCita plugin already installed.This plugin shows your free time slot on your blog and allows you to book appointments with your clients 24x7x365. Very easy Ajax interface. Easy to setup and can be controlled completely from powerful admin area.onclick="wpshd_ntf_dismiss();this.parentNode.remove()"onclick="wpshd_ntf_dismiss_switch()"onclick="wpshd_ntf_connect_click()"onclick="wpshd_ntf_turn_on_click()"vcitaSchedulerDataVcitaMixpmanMixpMan/wp-json/vcita/v1/appointments[vcita-scheduler]