Impact
Unauthenticated attackers can delete any file on the server due to missing validation of the file path in the extraction function. The vulnerability allows deletion of critical files such as wp-config.php, which can lead to remote code execution. The CVSS score of 9.1 reflects the high confidentiality, integrity, and availability impact of this flaw.
Affected Systems
The affected product is the VikAppointments Services Booking Calendar plugin for WordPress, version 1.2.21 and earlier. All installations using these versions are vulnerable, regardless of the WordPress core or other plugins in use.
Risk and Exploitability
The flaw can be exploited by sending a crafted HTTP request that includes the old_vapcfN parameter pointing to a target file. The attacker does not need any credentials and only requires the presence of a file‑type custom field on the confirmation page. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the CVSS rating indicates that successful exploitation would be catastrophic and could affect an entire site.
OpenCVE Enrichment