Impact
The VikAppointments Services Booking Calendar plugin version 1.2.20 and earlier includes an unauthenticated SQL injection flaw that allows arbitrary SQL statements to be executed through unsanitized input parameters. An attacker can read, modify, or delete data stored in the WordPress database, which undermines confidentiality, integrity, and availability of site data and can lead to broader system compromise if privileged database operations are possible.
Affected Systems
WordPress sites running the VikAppointments Services Booking Calendar plugin up to and including version 1.2.20 are affected. Any installation of the e4jvikwp:VikAppointments Services Booking Calendar plugin exposed to a public WordPress environment is at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The flaw requires no authentication and the description notes unsanitized input; therefore it is inferred that the attack vector is network access to the WordPress site’s public front-end. EPSS data is not available, and the vulnerability is not listed in CISA KEV, but the high severity and lack of authentication requirement imply a high likelihood of real-world exploitation.
OpenCVE Enrichment