← WordPress Vulnerabilities
WordPress security by component

Appointments

Appointments is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 18, 2025; the highest published CVSS base score is 9.8.

Plugin slug: appointments

CVE-2017-20206: Appointments: Code execution

Appointments is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedOct 18, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for appointments
Safe version
Oct 18, 2025 CVE-2017-20206
Appointments: Code execution
Appointments is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVDPending