Executive brief
VikAppointments is a WordPress plugin used to manage appointment and service bookings on websites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete the entire database without logging in, potentially exposing customer data, appointment records, and user credentials.
Technical details
The vulnerability is a classic SQL injection flaw in VikAppointments Services Booking Calendar plugin versions up to 1.2.20. The injection point is unauthenticated—no login is required to exploit it—and allows attackers to execute arbitrary SQL commands directly against the underlying database. An attacker can retrieve sensitive data (customer information, appointment details, user accounts), modify records, or delete data entirely. The vulnerability was patched in version 1.2.21; users should update immediately as exploitation is expected to become widespread.
Affected products
- VikAppointments Services Booking Calendar <= 1.2.20
Timeline
- 2026-09-03: disclosed: Vulnerability disclosed on NVD
- 2026-09-03: advisory: Patchstack advisory published
- 2026-09-03: patched: Patched in version 1.2.21