What is CVE-2026-14433?
CVE-2026-14433 is a Stored Cross-Site Scripting vulnerability in the `business_id` parameter of the Online Booking & Scheduling Calendar for WordPress by vcita plugin, affecting versions up to 4.6.0. It allows unauthenticated attackers to inject malicious scripts due to insufficient input sanitization and output escaping. Sites using this plugin should immediately update to a version above 4.6.0.
Azərbaycanca: CVE-2026-14433, WordPress üçün vcita Onlayn Rezervasiya və Planlaşdırma Təqvimi plaginində `business_id` parametri vasitəsilə Stored Cross-Site Scripting zəifliyidir. Bu, autentifikasiya olunmamış hücumçulara zərərli skriptlər yerləşdirməyə imkan verir. Plagindən istifadə edən saytlar dərhal 4.6.0-dan yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What type of security vulnerability is CVE-2026-14433 in the Online Booking & Scheduling Calendar for WordPress by vcita plugin?
It is a Stored Cross-Site Scripting (XSS) vulnerability.
To what version should the plugin be updated to mitigate CVE-2026-14433?
The plugin should be updated to a version above 4.6.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.