Contact Form and Calls to Action by vcita Missing Authorization Vulnerability on WordPress

Vulnerability

A vulnerability exists in the Contact Form and Calls To Action by vcita plugin for WordPress, in all versions through 2.7.1. The issue arises from a lack of proper capability checks in the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions. This flaw allows authenticated attackers with subscriber-level access and above to unauthorizedly modify widget settings, enabling or disabling widgets at will.

Impact

Exploitation of this vulnerability allows for unauthorized modification of widget settings, specifically enabling or disabling widgets on the site.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.1
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.