Impact
The VikAppointments Services Booking Calendar plugin version 1.2.19 or earlier contains an unauthenticated SQL injection flaw. An attacker can supply a malicious value for the parameter that controls the sorting order of the public reviews list, causing the plugin to incorporate the value directly into a database query without validation or sanitization. This flaw allows the attacker to execute arbitrary SQL statements and read data from the WordPress database, including sensitive information such as user credentials, without needing to authenticate or possessing special privileges.
Affected Systems
WordPress sites running the VikAppointments Services Booking Calendar plugin up to and including version 1.2.19 are affected. Any installation that has not been updated beyond this release is vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating a high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only the ability to craft a normal HTTP request to the booking page; no authentication or elevated privileges are needed. The lack of input validation – a CWE‑89 condition – makes the attack vector straightforward for automated scanners and malicious actors.
OpenCVE Enrichment