---
id: CVE-2026-87115
title: >-
  The VikAppointments Services Booking Calendar plugin for WordPress is
  vulnerable to arbitrary file deletion due to insufficient file path validation
  in the extract function in all versions up to, and including, 1.2.21
summary: >-
  The VikAppointments Services Booking Calendar plugin for WordPress is
  vulnerable to arbitrary file deletion due to insufficient file path validation
  in the extract function in all versions up to, and including, 1.2.21. This
  makes it poss…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
vendor: e4jvikwp
product: VikAppointments Services Booking Calendar
affected:
  - vikappointments_services_booking_calendar <= 1.2.21
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T07:16:48.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87115'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/controllers/confirmapp.php#L88
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/libraries/customfields/types/file.php#L131
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/libraries/customfields/types/file.php#L53
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/vikappointments.php#L237
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/site/controllers/confirmapp.php#L88
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/site/helpers/libraries/customfields/types/file.php#L131
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/site/helpers/libraries/customfields/types/file.php#L53
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/vikappointments.php#L237
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3721264%40vikappointments&new=3721264%40vikappointments
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/75fc5df5-a774-4fe1-8452-d35ba7b69081?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T07:40:49.053Z'
---

## Overview

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode, as this field is not created by default during plugin installation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
