Arbitrary File Deletion in VikAppointments Services Booking Calendar Plugin for WordPress
CVE-2026-87115
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-87115?
The VikAppointments Services Booking Calendar plugin for WordPress exhibits a significant security flaw, allowing arbitrary file deletion due to insufficient file path validation in the extraction process. This vulnerability affects all versions up to and including 1.2.21, enabling unauthenticated attackers to delete arbitrary files on the server. Such deletions can lead to severe consequences, including the potential for remote code execution if critical files, like wp-config.php, are targeted. Exploiting this vulnerability necessitates at least one File-type custom field to be published on the confirmation page shortcode, which is not included by default upon plugin installation.
Affected Version(s)
VikAppointments Services Booking Calendar 0 <= 1.2.21