VikAppointments Services Booking Calendar
VikAppointments Services Booking Calendar provides service booking calendars and appointment scheduling features for WordPress websites.
VikAppointments Services Booking Calendar (vikappointments) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 7.5.
vikappointmentsCVE-2026-15918: VikAppointments public review sorting permits SQL injection
VikAppointments Services Booking Calendar through 1.2.19 uses an unauthenticated request value that controls the sort order of a public reviews list when constructing a database query without adequate validation or parameterization. An attacker can inject SQL through a normal public booking page and use time-based or other database behavior to extract sensitive WordPress data, including credential material. The CNA record points to the review-query and public search-view code but does not disclose the request parameter's name.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-15918
VikAppointments public review sorting permits SQL injection
VikAppointments Services Booking Calendar through 1.2.19 uses an unauthenticated request value that controls the sort order of a public reviews list when constructing a database query without adequate validation or parameterization. An attacker can inject SQL through a normal public booking page and use time-based or other database behavior to extract sensitive WordPress data, including credential material. The CNA record points to the review-query and public search-view code but does not disclose the request parameter's name.
|
> 1.2.19 |
CVE7.5
NVDPending
|
| Jan 21, 2025 |
CVE-2025-22719
VikAppointments Services Booking Calendar: Cross-site scripting
VikAppointments Services Booking Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVDPending
|