PT-2026-104544 · WordPress · Vikappointments Services Booking Calendar
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VikAppointments Services Booking Calendar versions prior to 1.2.22
Description
Insufficient file path validation in the
extract() function allows unauthenticated attackers to delete arbitrary files on the server. This issue can lead to remote code execution if critical files, such as wp-config.php, are deleted. Exploitation is possible provided that at least one File-type custom field is published on the confirmation page shortcode, as this configuration is not active by default.Recommendations
Update to a version newer than 1.2.21.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vikappointments Services Booking Calendar