← WordPress Vulnerabilities
WordPress security by component

VikAppointments Services Booking Calendar

VikAppointments Services Booking Calendar provides service booking calendars and appointment scheduling features for WordPress websites.

VikAppointments Services Booking Calendar (vikappointments) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 7.5.

Plugin slug: vikappointments

CVE-2026-15918: VikAppointments public review sorting permits SQL injection

VikAppointments Services Booking Calendar through 1.2.19 uses an unauthenticated request value that controls the sort order of a public reviews list when constructing a database query without adequate validation or parameterization. An attacker can inject SQL through a normal public booking page and use time-based or other database behavior to extract sensitive WordPress data, including credential material. The CNA record points to the review-query and public search-view code but does not disclose the request parameter's name.

PublishedAug 05, 2026
Known safe version> 1.2.19
Published vulnerabilities for vikappointments
Safe version
Aug 05, 2026 CVE-2026-15918
VikAppointments public review sorting permits SQL injection
VikAppointments Services Booking Calendar through 1.2.19 uses an unauthenticated request value that controls the sort order of a public reviews list when constructing a database query without adequate validation or parameterization. An attacker can inject SQL through a normal public booking page and use time-based or other database behavior to extract sensitive WordPress data, including credential material. The CNA record points to the review-query and public search-view code but does not disclose the request parameter's name.
> 1.2.19
CVE7.5
NVDPending
Jan 21, 2025 CVE-2025-22719
VikAppointments Services Booking Calendar: Cross-site scripting
VikAppointments Services Booking Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.1
NVDPending