Skip to content
eastbaycyber

CVE-2026-87115: VikAppointments File Deletion

CVSS · Critical
9.1
In CISA KEV
No
Published
Oct 3
CVE explainers 10 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-03
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2026-87115 affects the VikAppointments Services Booking Calendar WordPress plugin through version 1.2.21. - The critical flaw may allow unauthenticated arbitrary file deletion when a File-type custom field is exposed through the confirmation-page shortcode. - No fixed version, verified public proof of concept, or confirmed active exploitation was identified. - Disable the affected functionality or plugin, protect backups, and investigate suspicious requests and file changes.

AnalystImpact · assess the risk

Are You Affected?

CVE-2026-87115 is a VikAppointments vulnerability affecting the Services Booking Calendar WordPress plugin through version 1.2.21, inclusive. The flaw is in file handling for custom fields and may be reachable without WordPress authentication when the relevant plugin functionality is enabled.

Field Details
CVE CVE-2026-87115
CVSS 9.1, Critical
Attack vector Network-based according to the unauthenticated web exploitation description; the official vector string was not included in the supplied NVD response
Authentication required None, according to the NVD description
Privileges required None is the expected interpretation of the unauthenticated description; confirm against the full CVSS vector when available
Affected product VikAppointments Services Booking Calendar for WordPress
Affected versions All versions up to and including 1.2.21
Fixed version None identified in the available NVD record or references
Patch available No confirmed patch identified

The exposure is conditional rather than universal. At least one File-type custom field must be configured and published through the plugin’s confirmation-page shortcode. The field is not created by default during installation, so sites using only default settings may not expose the vulnerable path.

Review the configuration of every WordPress site using VikAppointments rather than assuming that a default deployment is safe. Record the installed version, identify File-type custom fields, and determine whether those fields are exposed through a public confirmation workflow.

Analyst’s Take: Version inventory alone is not enough to prioritize this issue because the documented attack path also depends on a published File-type custom field and confirmation-page shortcode. Start with sites where administrators enabled file collection or custom booking fields, then disable the affected functionality or the plugin while vendor status remains unresolved.

The supplied research does not establish whether every version after 1.2.21 remains vulnerable. Until the vendor confirms a fixed release, treat newer versions as unverified, not automatically safe.

The Fix, If You’re in a Hurry

No vendor-confirmed fixed version was identified in the available sources. Check the official VikAppointments release channel before upgrading, and do not describe an unverified later release as a fix.

If a vendor-confirmed security release becomes available:

  1. Upgrade to the specific fixed version.
  2. Review the vendor advisory and release notes.
  3. Verify the installed version.
  4. Test booking, confirmation, and file-upload workflows.
  5. Review logs and file-integrity telemetry for suspicious activity.

If no upgrade is available, disable VikAppointments or remove the affected functionality. At minimum:

  • Disable every File-type custom field.
  • Stop publishing the confirmation-page shortcode that exposes those fields.
  • Restrict public access to affected booking workflows where possible.
  • Protect backups from modification by the WordPress web process.
  • Monitor for unexpected file deletions and WordPress configuration changes.

These steps reduce the documented attack path but should not be treated as a complete security fix unless the vendor confirms that no other route reaches the vulnerable file-processing code.

WP-CLI Mitigation

Use WP-CLI to identify the installed plugin and deactivate it if necessary. The plugin slug may vary by packaging, so verify the result rather than relying blindly on the command output:

wp plugin list --name=vikappointments --fields=name,status,version,update --format=table
wp plugin deactivate vikappointments

For a multisite network, assess whether the plugin is network-active and apply the change at the appropriate scope:

wp plugin list --network --fields=name,status,version,update --format=table
wp plugin deactivate vikappointments --network

Do not run wp plugin update and assume that the latest release resolves the issue when no fixed version has been confirmed. If the vendor publishes a fixed version, use the exact version from the vendor advisory or approved release process:

wp plugin update vikappointments --version=<vendor-confirmed-fixed-version>
wp plugin list --name=vikappointments --fields=name,status,version

Before making changes, take a protected backup. Store at least one copy outside the web server and ensure that the WordPress web process cannot overwrite it.

If the plugin must remain installed for operational reasons, remove or disable File-type custom fields and the confirmation-page shortcode through the plugin’s administrative configuration. Test that unauthenticated users cannot submit or process those fields.

How This Vulnerability Works

The flaw is an insufficient file-path validation problem in VikAppointments’ File-type custom-field implementation. The confirmation controller processes uploaded or custom-field data, while the File-type custom-field code uses an extract function associated with file handling. According to the NVD description, attacker-controlled path data can reach deletion logic without adequate validation.

This creates an arbitrary file deletion condition. An unauthenticated attacker may be able to submit a crafted request through the exposed confirmation workflow and cause the server process to delete a file outside the intended upload location. The impact depends on filesystem permissions and the exact request path available on the deployment.

Deletion of wp-config.php is particularly serious. Removing this file can disrupt the site and, depending on WordPress and server configuration, may create conditions that help an attacker trigger a setup or reconfiguration flow. The available material describes this as a potential route to remote code execution, not as a guaranteed result on every installation.

Other sensitive targets may include:

  • .htaccess
  • WordPress core files
  • Plugin files
  • Theme files
  • Application data
  • Uploaded content

The exploitation prerequisite matters operationally: a File-type custom field must be published through the confirmation-page shortcode. Because this configuration is not created by default, prioritize sites where administrators intentionally enabled file collection or custom booking fields.

Referenced Code Locations

The NVD-linked source references identify relevant code in confirmapp.php and the File-type custom-field implementation in file.php. The available retrieval environment could not independently reproduce the source lines because WordPress Trac returned HTTP 403. This explanation therefore relies on the NVD description and linked source locations rather than claiming a line-by-line source audit.

The affected code locations include references for versions 1.2.19 and 1.2.21:

  • site/controllers/confirmapp.php
  • site/helpers/libraries/customfields/types/file.php
  • The plugin bootstrap and version metadata

Severity Explained

NVD reports a CVSS score of 9.1, Critical. However, the supplied NVD response did not include the CVSS vector string. A score alone is insufficient to safely reconstruct the individual CVSS components, so this article does not infer values for attack complexity, user interaction, scope, confidentiality, integrity, or availability impact.

The available description supports the following practical interpretation:

  • Unauthenticated: The attacker does not need a WordPress account according to the NVD description.
  • Remote: Exploitation occurs through a web-accessible WordPress plugin workflow.
  • High impact: Arbitrary file deletion can affect site availability and integrity and may provide a path to broader compromise.
  • Conditional exposure: The vulnerable File-type custom field and confirmation-page configuration must be present.

Administrators should retrieve the complete NVD JSON record or authoritative CVE data before using the vector string in compliance reports, risk models, or automated prioritization. Do not generate a vector by reverse-engineering it from the 9.1 score.

Is CVE-2026-87115 Being Exploited?

CVE-2026-87115 is not listed in CISA’s Known Exploited Vulnerabilities catalog as of October 3, 2026. No CISA date-added entry, remediation due date, or ransomware campaign designation applies.

This means there is no CISA KEV-based evidence of known exploitation, not that exploitation is impossible.

The reviewed material did not identify confirmed exploitation in the wild. It also did not identify a reliable public proof of concept, a verified GitHub exploit repository, or an authoritative vendor advisory describing active attacks. The appropriate status is therefore:

Active exploitation not confirmed; verified public proof of concept not identified.

Do not use that status to defer remediation. The combination of unauthenticated access, arbitrary file deletion, and a potential route to remote code execution warrants urgent action on exposed installations.

ResponderRunbook · act now

Detecting the Vulnerability in Your Environment

Start by identifying all WordPress sites running VikAppointments and recording the installed version. Review each plugin’s custom-field configuration for File-type fields and determine whether those fields are exposed through a confirmation-page shortcode.

Configuration review is essential because version inventory alone does not show whether the documented exploitation prerequisite exists.

Next, search web-server access logs for unauthenticated requests associated with the VikAppointments plugin and confirmation workflow. There is no supplied canonical request signature, endpoint name, or vendor detection rule, so searches for confirmapp and the plugin path are starting points rather than proof of exploitation.

Correlate suspicious requests with:

  • File-integrity events
  • Application errors
  • Unexpected file disappearance
  • WordPress configuration changes
  • Changes to plugin or theme files
  • Unusual administrator or setup activity

A broader explanation of asset and exposure discovery is available in our guide to attack surface management.

Log Searches

A basic Apache or Nginx log search can identify requests containing the plugin path or confirmation-controller string:

zgrep -hEi \
  '/wp-content/plugins/vikappointments/|confirmapp|vikappointments' \
  /var/log/nginx/access.log* /var/log/apache2/access.log* 2>/dev/null

Look for unauthenticated POST requests, unusual query parameters, repeated requests from the same source, HTTP 200 or 500 responses, and activity immediately before unexpected file disappearance.

The following pattern is a useful triage filter, but it is not a complete exploit signature:

zgrep -hEi \
  '"POST [^"]*(confirm|vikappointments)[^"]* HTTP/[^\"]+"|/wp-content/plugins/vikappointments/' \
  /var/log/nginx/access.log* /var/log/apache2/access.log* 2>/dev/null

File Integrity Checks

Check high-value files and compare them with a known-good backup or WordPress integrity baseline:

for f in wp-config.php .htaccess wp-admin/index.php wp-includes/version.php; do
  [ -e "$f" ] && sha256sum "$f" || echo "MISSING: $f"
done

wp core verify-checksums

Also review filesystem audit or EDR telemetry for unlink and rename operations under the web root. A suspicious sequence may involve:

  1. A request to a VikAppointments confirmation endpoint.
  2. An application error or unusual response.
  3. Deletion of wp-config.php, .htaccess, a plugin file, or an upload-directory object.
  4. Subsequent site errors or setup prompts.

Organizations evaluating additional malware and endpoint monitoring may also review Malwarebytes alongside their existing EDR and file-integrity controls.

The absence of relevant logs does not prove that exploitation did not occur. Log retention, reverse proxies, web application firewalls, and application-level routing may obscure the original request.

Incident Response Considerations

If you identify suspicious requests or missing files:

  1. Preserve web-server, proxy, WAF, PHP, and WordPress logs.
  2. Restrict or isolate the affected site if business operations allow.
  3. Disable VikAppointments and its File-type custom fields.
  4. Protect and preserve backups before restoring files.
  5. Compare WordPress core, plugin, and theme files against trusted versions.
  6. Rotate WordPress administrator, database, hosting, SSH, and API credentials if compromise is possible.
  7. Review administrator accounts, scheduled tasks, uploads, and recently modified files.
  8. Investigate whether wp-config.php or other sensitive files were accessed or deleted.
  9. Rebuild from a known-good source if file integrity cannot be established.
  10. Keep compensating controls in place until a vendor-confirmed fix is installed and validated.

References and Further Reading

The primary record is the NVD entry for CVE-2026-87115. It provides the vulnerability description, affected-version information through 1.2.21, and the reported 9.1 CVSS score. Obtain the complete vector from the full NVD record before using it in a formal security bulletin.

Resource Purpose
NVD: CVE-2026-87115 Primary CVE record and severity information
VikAppointments confirmapp.php, version 1.2.19 NVD-linked confirmation-controller source reference
VikAppointments file.php, version 1.2.19, line 131 NVD-linked File-type custom-field source reference
VikAppointments file.php, version 1.2.19, line 53 Additional NVD-linked file-handling reference
VikAppointments plugin bootstrap, version 1.2.19 Plugin version and bootstrap reference
VikAppointments confirmapp.php, version 1.2.21 Reference for the affected-version code path

No authoritative vendor advisory or confirmed fixed version was identified in the supplied research. Before closing the incident or removing compensating controls, verify the official VikAppointments release channel and confirm that a later release explicitly addresses CVE-2026-87115.

Until then, prioritize exposed installations by disabling the documented attack path, preserving protected backups, and reviewing requests and file-integrity events for signs of deletion.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-10-03

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.