Junglewise Threat Intelligence

CVE-2026-15282: WordPress Instant Appointment arbitrary file upload in insapp_upload_image_as_attachment

CVE-2026-15282 · Severity: critical · CVSS 9.8 · Published 2026-07-10

Executive brief

The Instant Appointment plugin for WordPress, used for managing bookings, contains a critical security flaw that allows anyone to upload files to the website's server. Because the plugin does not check what kind of files are being uploaded, an attacker could upload malicious scripts. This could lead to a complete takeover of the website, theft of customer data, or a total service outage.

Technical details

The Instant Appointment plugin for WordPress (up to version 1.2) suffers from an unrestricted file upload vulnerability (CWE-434). The root cause is a lack of file type validation within the 'insapp_upload_image_as_attachment' function, which is accessible via AJAX. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload arbitrary files, such as PHP scripts, to the server. Successful exploitation allows for remote code execution (RCE), potentially leading to full system compromise. The vulnerability is present in both administrative and front-end AJAX handlers.

Affected products

  • tenteeglobal Instant Appointment <= 1.2

Timeline

  • 2026-07-10: disclosed: CVE published by Wordfence and NVD

References