Unauthenticated SQL Injection in VikAppointments Booking Calendar by Vik App
CVE-2026-84768

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84768?

VikAppointments Services Booking Calendar versions up to 1.2.20 are vulnerable to an unauthenticated SQL injection flaw. This vulnerability allows attackers to manipulate database queries, potentially leading to unauthorized data access and database compromise, posing significant risks to users who rely on this booking system.

Affected Version(s)

VikAppointments Services Booking Calendar <= 1.2.20

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez) | Patchstack Bug Bounty Program
.