Unauthenticated SQL Injection in VikAppointments Service Booking Calendar Plugin
CVE-2026-15918
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-15918?
The VikAppointments Service Booking Calendar plugin for WordPress contains a vulnerability that allows for unauthenticated SQL injection. This occurs when data from incoming requests is improperly handled, specifically in parameters used for sorting public reviews. An attacker can exploit this flaw by injecting malicious SQL queries through the booking page, enabling them to access sensitive information, including user credentials stored in the WordPress database, without requiring any form of authentication or privileges. Proper validation and sanitation of input parameters are essential to prevent these types of attacks.
Affected Version(s)
VikAppointments Services Booking Calendar 0 <= 1.2.19