Unauthenticated SQL Injection in VikAppointments Booking Calendar by Vik App
CVE-2026-84768
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2026-84768?
VikAppointments Services Booking Calendar versions up to 1.2.20 are vulnerable to an unauthenticated SQL injection flaw. This vulnerability allows attackers to manipulate database queries, potentially leading to unauthorized data access and database compromise, posing significant risks to users who rely on this booking system.
Affected Version(s)
VikAppointments Services Booking Calendar <= 1.2.20
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Supakiad S. (m3ez) | Patchstack Bug Bounty Program