← WordPress Vulnerabilities
WordPress security by component

Instant Appointment

Instant Appointment is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: instant-appointment

CVE-2026-15282: Instant Appointment: Dangerous file upload

Instant Appointment is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 1.2.

PublishedJul 10, 2026
Known safe version> 1.2
Safe version
Jul 10, 2026 CVE-2026-15282
Instant Appointment: Dangerous file upload
Instant Appointment is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 1.2.
> 1.2
CVE9.8
NVDPending
Jan 22, 2025 CVE-2025-23672
Instant Appointment: Cross-site scripting
Instant Appointment is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Dec 16, 2024 CVE-2024-54361
Instant Appointment: SQL injection
Instant Appointment is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVDPending