Arbitrary File Deletion in VikAppointments Services Booking Calendar Plugin for WordPress
CVE-2026-87115

9.1CRITICAL

What is CVE-2026-87115?

The VikAppointments Services Booking Calendar plugin for WordPress exhibits a significant security flaw, allowing arbitrary file deletion due to insufficient file path validation in the extraction process. This vulnerability affects all versions up to and including 1.2.21, enabling unauthenticated attackers to delete arbitrary files on the server. Such deletions can lead to severe consequences, including the potential for remote code execution if critical files, like wp-config.php, are targeted. Exploiting this vulnerability necessitates at least one File-type custom field to be published on the confirmation page shortcode, which is not included by default upon plugin installation.

Affected Version(s)

VikAppointments Services Booking Calendar 0 <= 1.2.21

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zickzick2
.