Executive brief
The Instant Appointment plugin for WordPress, used for managing bookings, contains a critical security flaw that allows anyone to upload files to the website's server. Because the plugin does not check what kind of files are being uploaded, an attacker could upload malicious scripts. This could lead to a complete takeover of the website, theft of customer data, or a total service outage.
Technical details
The Instant Appointment plugin for WordPress (up to version 1.2) suffers from an unrestricted file upload vulnerability (CWE-434). The root cause is a lack of file type validation within the 'insapp_upload_image_as_attachment' function, which is accessible via AJAX. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload arbitrary files, such as PHP scripts, to the server. Successful exploitation allows for remote code execution (RCE), potentially leading to full system compromise. The vulnerability is present in both administrative and front-end AJAX handlers.
Affected products
- tenteeglobal Instant Appointment <= 1.2
Timeline
- 2026-07-10: disclosed: CVE published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/instant-appointment/trunk/includes/ajax/ajax_services.php
- https://plugins.trac.wordpress.org/browser/instant-appointment/trunk/includes/front-end/ajax/login_ajax.php
- https://plugins.trac.wordpress.org/browser/instant-appointment/trunk/includes/front-end/ajax/login_ajax.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/097b1530-64fa-45b2-85f3-c6a2311405b5?source=cve