CRITICAL 9.1 CVE-2026-87115 Published 3 Oct 2026

VikAppointments Booking Calendar Plugin Arbitrary File Deletion Vulnerability

Worried this affects your website?

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function.

  • Affected versions: all versions up to and including 1.2.21.
  • Attackers: unauthenticated attackers can delete arbitrary files on the server.
  • Impact: can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
  • Precondition: at least one File-type custom field must be published on the confirmation page shortcode; this field is not created by default during plugin installation.

Reference: CVE-2026-87115 on NVD

← Back to Security News