Sceawere

Vulnerability Detail

CVE-2026-87115UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

VikAppointments Arbitrary File Deletion

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
e4jvikwp
Product
VikAppointments Services Booking Calendar
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode, as this field is not created by default during plugin installation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-03T07:16:48.347Z",
  "pubdate": "2026-10-03T07:16:48.347Z",
  "executiveSummary": "The VikAppointments Services Booking Calendar plugin for WordPress, in versions up to and including 1.2.21, contains a critical security vulnerability involving improper neutralization of input during file path processing. This flaw enables unauthenticated remote attackers to perform arbitrary file deletion on the underlying server filesystem.\nThe vulnerability stems from insufficient validation of file paths within the plugin's extract function. By manipulating input parameters, an attacker can bypass intended directory constraints to delete sensitive system or application files. Successful exploitation carries severe risk, as the deletion of critical configuration files, such as 'wp-config.php', can force a site reset or lead to full remote code execution through subsequent reinstallation or environment compromise.\nExploitation requires the presence of at least one 'File-type' custom field enabled on the confirmation page shortcode, a configuration that is not default but significantly widens the attack surface for public-facing booking forms. Given the potential for complete site takeover, this vulnerability is classified as critical, necessitating immediate remediation by site administrators through plugin updates or compensating security controls.",
  "technicalDetails": "The root cause of the vulnerability resides in the 'extract' function within the VikAppointments plugin. The implementation fails to adequately sanitize or validate user-supplied file path inputs before performing filesystem operations. By failing to implement robust path normalization or strict allow-listing of target directories, the plugin allows an attacker to inject directory traversal sequences or absolute paths, effectively escaping the intended directory scope.\nThe exploitation flow begins with the attacker identifying a publicly accessible page utilizing the VikAppointments confirmation shortcode, specifically configured with a 'File-type' custom field. Because the plugin logic processes these fields through the vulnerable 'extract' function without verifying the integrity or the intended destination of the file operation, an attacker can supply a malicious path in the request payload.\nWhen the input is processed, the function interprets the user-supplied string as a valid file handle. If the server process runs with sufficient filesystem permissions, the underlying PHP operation (typically an unlink-like action or derivative) executes against the targeted file. An attacker can craft a payload targeting critical application components, most notably 'wp-config.php'. By deleting this file, an attacker can trigger a WordPress 'installation' state, allowing them to overwrite the database connection strings or inject malicious configuration settings.\nThis vulnerability is particularly dangerous because it requires zero authentication, making it accessible to any remote actor capable of reaching the booking form. The network exposure is broad, as the endpoint is typically intended for public interaction. The post-exploitation impact extends beyond mere denial-of-service; the destruction of core WordPress components facilitates a pathway to total remote code execution (RCE) by coercing the application into an insecure state where a malicious actor can gain administrative access or deploy persistent backdoors into the environment.\nVersions 1.2.21 and earlier are confirmed to be vulnerable. The absence of sufficient input checking during the extraction process represents a failure in secure coding practices related to I/O operations, necessitating a comprehensive review of path handling logic within the plugin codebase."
}
CVE-2026-87115: VikAppointments Arbitrary File Deletion (CRITICAL Severity, CVSS: 9.1) | Sceawere