Impact
The VikAppointments Services Booking Calendar plugin version 1.2.20 and earlier contains an unauthenticated SQL injection flaw. An attacker can inject arbitrary SQL statements into the plugin’s database queries, potentially reading, modifying, or deleting sensitive data stored by the WordPress site. This undermines the confidentiality, integrity, and availability of the application’s data store and can lead to broader system compromise if the database allows privileged operations.
Affected Systems
WordPress sites running the VikAppointments Services Booking Calendar plugin up to and including version 1.2.20 are affected. Any installation with e4jvikwp:VikAppointments Services Booking Calendar deployed in a public WordPress environment is at risk.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is rated critical. The lack of authentication requirements and the absence of collateral damage mitigation make exploitation straightforward for anyone with network access. EPSS data is not available and the issue is not listed in the CISA KEV catalog, but the high severity score and the straightforward exploitation path signify a high likelihood of real-world attacks.
OpenCVE Enrichment