CVE-2026-84768
moderateUnauthenticated SQL Injection in VikAppointments Services Booking Calendar (WordPress)
VikAppointments Services Booking Calendar, a WordPress appointment-booking plugin, is vulnerable to an unauthenticated SQL injection (CWE-89) in all versions up to and including 1.2.20. Because the flaw requires no authentication and is reachable over the network, any remote attacker who can reach the affected site can submit crafted input to the vulnerable request and inject SQL into the plugin's database queries. Per the CVSS vector, successful exploitation primarily exposes confidential database contents (confidentiality: high, integrity: none, availability: low), potentially including booking and customer records. Any WordPress site running the plugin at version 1.2.20 or earlier is affected; this is a niche booking plugin, so the plausible install base is in the low thousands of sites rather than millions. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns only about 0.2% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented at this time.
What to do: Update VikAppointments Services Booking Calendar to a version newer than 1.2.20 as soon as a patched release is available, and verify the installed version on every managed site. If updating must wait, consider temporarily deactivating the plugin since the flaw is exploitable without authentication, and review web-server logs for suspicious SQL-error or injection-pattern requests against the site. Because confidentiality is the primary impact, consider auditing the WordPress database (booking/customer tables) for signs of unauthorized reads if compromise is suspected.
| vikwp (e4j) VikAppointments Services Booking Calendar (WordPress plugin) | <= 1.2.20 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.