Skip to main content
Vulnerability Database/CVE-2026-87115

CVE-2026-87115: VikAppointments WordPress Plugin RCE Vulnerability

CVE-2026-87115 is an arbitrary file deletion flaw in VikAppointments WordPress plugin that enables remote code execution. Unauthenticated attackers can delete critical files like wp-config.php. This article covers technical details, affected versions, exploitation requirements, and mitigation strategies.

Published:

CVE-2026-87115 Overview

CVE-2026-87115 is an arbitrary file deletion vulnerability in the VikAppointments Services Booking Calendar plugin for WordPress. The flaw affects all versions up to and including 1.2.21. The vulnerability stems from insufficient file path validation in the extract function used by the File-type custom field handler. Unauthenticated attackers can delete arbitrary files on the server, including wp-config.php, which commonly leads to remote code execution. Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode.

Critical Impact

Unauthenticated remote attackers can delete arbitrary server files, including wp-config.php, enabling site takeover and remote code execution.

Affected Products

  • VikAppointments Services Booking Calendar plugin for WordPress
  • All versions up to and including 1.2.21
  • WordPress sites publishing a File-type custom field on the confirmation page shortcode

Discovery Timeline

  • 2026-10-03 - CVE-2026-87115 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-87115

Vulnerability Analysis

The vulnerability resides in the VikAppointments confirmation application controller and the File-type custom field helper. The extract function processes file paths submitted through the confirmation page shortcode without properly validating or sanitizing them. An unauthenticated attacker can supply a crafted path that resolves outside the intended upload directory, causing the plugin to delete arbitrary files accessible to the web server process.

Deleting wp-config.php is particularly damaging. When WordPress loads without a configuration file, it enters the installation flow, allowing an attacker to point the site at an attacker-controlled database and seed an administrator account. From there, the attacker can upload plugins or themes to achieve remote code execution.

The weakness is classified under CWE-22: Improper Limitation of a Pathname to a Restricted Directory. The EPSS score at publication is 0.881% (percentile 57.897).

Root Cause

The root cause is missing path validation inside the File-type custom field handler. The plugin trusts user-supplied file identifiers and passes them to a deletion routine without constraining the resolved path to the plugin's upload directory. Reviewers can inspect the affected logic in the VikAppointments Custom Fields File Type helper and the Confirm App Controller.

Attack Vector

The attack vector is network-based and requires no authentication or user interaction. The attacker submits a crafted request to the confirmation page shortcode endpoint, targeting the File-type custom field with a path traversal payload. Exploitation requires that the site operator has published at least one File-type custom field on the confirmation page, as this field is not created by default.

No verified public exploit is available. The vulnerability mechanism is documented in the Wordfence Vulnerability Intelligence advisory and the plugin changeset that addresses the issue.

Detection Methods for CVE-2026-87115

Indicators of Compromise

  • Missing or truncated wp-config.php, .htaccess, or index.php files in the WordPress root.
  • Unexpected WordPress installation screen (/wp-admin/install.php) returned to visitors.
  • POST requests to the VikAppointments confirmation shortcode endpoint containing .. sequences or absolute paths in File-type field parameters.
  • Web server access logs showing unauthenticated POSTs to confirmation URLs followed by 500 errors or site reinstallation prompts.

Detection Strategies

  • Audit WordPress sites for the VikAppointments plugin and confirm the version is 1.2.21 or earlier.
  • Review web server logs for requests to confirmation page URLs containing path traversal patterns in File-type field names or values.
  • Monitor file integrity on wp-config.php and other sensitive WordPress files using host-based file integrity monitoring.

Monitoring Recommendations

  • Enable WordPress audit logging for plugin activity, failed file operations, and administrator account creation events.
  • Alert on deletion events targeting WordPress core files, configuration files, or plugin assets.
  • Correlate web requests to VikAppointments endpoints with subsequent file system changes in the WordPress document root.

How to Mitigate CVE-2026-87115

Immediate Actions Required

  • Update the VikAppointments Services Booking Calendar plugin to a version later than 1.2.21 as soon as the vendor publishes a fixed release.
  • Remove or unpublish any File-type custom fields referenced by the confirmation page shortcode until the plugin is patched.
  • Verify integrity of wp-config.php and other WordPress core files; restore from backup if tampering is suspected.
  • Rotate database credentials and WordPress secret keys if file deletion or unauthorized reinstallation is observed.

Patch Information

The plugin repository changeset at plugins.trac.wordpress.org changeset 3721264 addresses the file path handling. Administrators should upgrade through the WordPress plugin manager once a release incorporating the fix is published. Compare installed plugin version against the VikAppointments main plugin file to confirm the current version.

Workarounds

  • Deactivate the VikAppointments plugin until a patched version is installed.
  • Remove File-type custom fields from the confirmation page shortcode to eliminate the exploitation precondition.
  • Restrict access to confirmation page URLs with a web application firewall rule blocking requests containing path traversal sequences in POST parameters.
  • Enforce least-privilege file system permissions so the web server user cannot delete files outside the plugin's upload directory.
bash
# Configuration example: block path traversal in confirmation POSTs (nginx)
location ~* /\?.*option=com_vikappointments.*view=confirm {
    if ($request_method = POST) {
        if ($args ~* "\.\./|%2e%2e%2f|/wp-config") { return 403; }
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.