{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vikappointments-services-booking-calendar--1.2.21/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vikwp:vikappointments_services_booking_calendar:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-87115"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VikAppointments Services Booking Calendar (\u003c= 1.2.21)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","vulnerability","file-deletion"],"_cs_type":"advisory","_cs_vendors":["VikWP"],"content_html":"\u003cp\u003eThe VikAppointments Services Booking Calendar plugin for WordPress (all versions up to and including 1.2.21) contains a critical arbitrary file deletion vulnerability. The flaw originates in the plugin's 'extract' function, which performs insufficient validation on file paths. An unauthenticated attacker can exploit this weakness by submitting malicious input to delete arbitrary files on the web server hosting the WordPress site.\u003c/p\u003e\n\u003cp\u003eThis vulnerability poses a severe risk, as the deletion of critical system or application files, such as 'wp-config.php', can force a site reconfiguration or lead to remote code execution (RCE). Successful exploitation is specifically gated by the presence of a 'File-type' custom field on a published confirmation page shortcode, a configuration that is not default but can be manually implemented by administrators. Given the prevalence of WordPress and the potential for total system compromise, immediate remediation is required.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to delete arbitrary files on the underlying web server. By targeting core WordPress files like 'wp-config.php', attackers can force the application to restart the installation process or access unauthorized data, ultimately facilitating remote code execution and full site takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the VikAppointments Services Booking Calendar plugin to the latest version, ensuring all instances are beyond 1.2.21.\u003c/li\u003e\n\u003cli\u003eAudit WordPress installations for the presence of the 'File-type' custom field within booking confirmation page shortcodes.\u003c/li\u003e\n\u003cli\u003eIf updating is not immediately possible, disable the use of custom 'File-type' fields in booking configurations until a patch can be applied.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP POST requests targeting the plugin's booking submission endpoints containing suspicious directory traversal sequences (e.g., ../, ..).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T08:54:06Z","date_published":"2026-10-03T08:54:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vikappointments-file-deletion/","summary":"The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion via insufficient path validation in the extract function, which can lead to remote code execution.","title":"Arbitrary File Deletion in VikAppointments Services Booking Calendar","url":"https://feed.craftedsignal.io/briefs/2026-10-vikappointments-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - VikAppointments Services Booking Calendar (\u003c= 1.2.21)","version":"https://jsonfeed.org/version/1.1"}