Description
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
Published: 2026-09-03
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The VikAppointments Services Booking Calendar plugin version 1.2.20 and earlier contains an unauthenticated SQL injection flaw. An attacker can inject arbitrary SQL statements into the plugin’s database queries, potentially reading, modifying, or deleting sensitive data stored by the WordPress site. This undermines the confidentiality, integrity, and availability of the application’s data store and can lead to broader system compromise if the database allows privileged operations.

Affected Systems

WordPress sites running the VikAppointments Services Booking Calendar plugin up to and including version 1.2.20 are affected. Any installation with e4jvikwp:VikAppointments Services Booking Calendar deployed in a public WordPress environment is at risk.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is rated critical. The lack of authentication requirements and the absence of collateral damage mitigation make exploitation straightforward for anyone with network access. EPSS data is not available and the issue is not listed in the CISA KEV catalog, but the high severity score and the straightforward exploitation path signify a high likelihood of real-world attacks.

Generated by OpenCVE AI on September 3, 2026 at 17:23 UTC.

Remediation

Vendor Solution

Update the WordPress VikAppointments Services Booking Calendar Plugin to the latest available version (at least 1.2.21).


OpenCVE Recommended Actions

  • Upgrade the VikAppointments Services Booking Calendar plugin to at least version 1.2.21.
  • If a patch cannot be applied immediately, disable or deactivate the plugin to eliminate the exposed input vectors.
  • Apply web‑application firewall or .htaccess rules to block suspicious requests to the plugin’s endpoints while remediation is pending.

Generated by OpenCVE AI on September 3, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
Title WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T17:33:46.904Z

Reserved: 2026-09-02T09:57:42.761Z

Link: CVE-2026-84768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:28.010

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:30:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')