ZeroHour

CVE-2026-84768

moderate

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar (WordPress)

CVSS 3.1
9.3 critical
EPSS
<1%p15
Published
()
Modified
AI analysis

VikAppointments Services Booking Calendar, a WordPress appointment-booking plugin, is vulnerable to an unauthenticated SQL injection (CWE-89) in all versions up to and including 1.2.20. Because the flaw requires no authentication and is reachable over the network, any remote attacker who can reach the affected site can submit crafted input to the vulnerable request and inject SQL into the plugin's database queries. Per the CVSS vector, successful exploitation primarily exposes confidential database contents (confidentiality: high, integrity: none, availability: low), potentially including booking and customer records. Any WordPress site running the plugin at version 1.2.20 or earlier is affected; this is a niche booking plugin, so the plausible install base is in the low thousands of sites rather than millions. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns only about 0.2% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented at this time.

What to do: Update VikAppointments Services Booking Calendar to a version newer than 1.2.20 as soon as a patched release is available, and verify the installed version on every managed site. If updating must wait, consider temporarily deactivating the plugin since the flaw is exploitable without authentication, and review web-server logs for suspicious SQL-error or injection-pattern requests against the site. Because confidentiality is the primary impact, consider auditing the WordPress database (booking/customer tables) for signs of unauthorized reads if compromise is suspected.

Affected
vikwp (e4j) VikAppointments Services Booking Calendar (WordPress plugin)<= 1.2.20
Estimated exposure
moderate≈1,000–10,000 WordPress sites (estimate; supplied data includes no install count) — The provided data lists no install counts, so this is an order-of-magnitude estimate based on the WordPress.org plugin directory, which lists VikAppointments as a niche booking plugin with an active-install base in the low thousands rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.