External risk intelligence

WordPress VikAppointments File Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-87115

The vulnerability affects a WordPress plugin designed to provide a booking calendar, which is a functional component typically deployed on public-facing websites to enable user interactions and appointments.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the VikAppointments Services Booking Calendar WordPress plugin. This issue allows unauthenticated attackers to delete arbitrary files on the server, potentially leading to unauthorized code execution by targeting critical system files. Exploitation is dependent on specific configurations involving file-type custom fields.

  • Attackers can delete server files remotely.
  • Critical risk if booking plugin is in use.
  • Confirm relevance and verify exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by leveraging a published File-type custom field on a confirmation page. Since the plugin does not adequately validate file paths in its extract function, an unauthenticated attacker can trick the system into deleting arbitrary files on the server. This could lead to critical system compromise, such as remote code execution, if a vital file like the configuration file is deleted.

  • No authentication required.
  • Unsanitized file path input.
  • Arbitrary file deletion, potential RCE.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to delete arbitrary files on the server, potentially leading to remote code execution. This risk is present when a File-type custom field is published on the confirmation page shortcode, which is not a default configuration.

  • Arbitrary file deletion on server.
  • Unauthenticated deletion via custom field.
  • Potential for remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WordPress plugin's arbitrary file deletion vulnerability likely falls under the responsibility of the application owner or the platform team managing the WordPress environment. The initial practical step is to identify all instances of the VikAppointments plugin, confirm if any are configured with file-type custom fields on confirmation pages, and determine their exposure and criticality. Once these factors are assessed, a remediation plan can be formulated.

  • Application owners should own the issue.
  • Verify plugin usage and custom field configuration.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the VikAppointments plugin for WordPress?

VikAppointments is a dedicated plugin for WordPress that adds a booking and scheduling system to a website. It is typically used by businesses to allow customers to view availability and book services directly through an online calendar interface.

What does CWE-22 mean in CVE-2026-87115?

CWE-22 refers to Improper Limitation of a Pathname to a Restricted Directory, commonly known as Path Traversal. In this context, the plugin fails to properly check file paths, which allows an attacker to manipulate the software into accessing or deleting files outside of the intended directory, potentially removing essential system files.

How can an attacker trigger this vulnerability?

The issue is triggered by submitting malicious input to the plugin's file extraction function. This does not happen automatically for all users; it only occurs if a File-type custom field has been explicitly enabled and published on a confirmation page shortcode. If this specific custom field is not in use, the vulnerable code path remains inaccessible.

Is my website at risk from this vulnerability?

Halo Surface Signal indicates that this plugin is commonly used on public-facing websites to handle user interactions like bookings. Because the vulnerability is accessible via the network without authentication, any site using an affected version with the specific File-type custom field configuration is likely at risk.

What steps should I take if I use VikAppointments?

First, inventory your WordPress environment to confirm if VikAppointments is installed and which version you are running. Check your booking confirmation pages to see if any File-type custom fields are currently active. If you find this configuration, prioritize updating the plugin or temporarily disabling the affected custom field until a secure update is applied.

References