A critical path traversal flaw (CVE-2026-87115) in the VikAppointments Services Booking Calendar plugin for WordPress, in all versions through 1.2.21, can let unauthenticated attackers delete any file on the server and possibly reach remote code execution.
What Is It
CVE-2026-87115 is an arbitrary file deletion vulnerability. It comes from insufficient file path validation in the plugin's extract function and is classified as CWE-22 (Path Traversal). Wordfence reported it, and NVD published it on October 3, 2026. The NVD record's status is currently "Received."
An unauthenticated attacker can use the flaw to delete arbitrary files on the server. The NVD description says this "can easily lead to remote code execution when the right file is deleted (such as wp-config.php)."
Why It Matters
Wordfence rates the flaw CVSS 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. That means:
- It can be exploited over the network
- Attack complexity is low
- No privileges or user interaction are needed
- The impact on integrity and availability is high
Deleting wp-config.php usually makes WordPress go back to its setup routine. That is why file deletion here can turn into a full site takeover.
There is one important limit. Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode. The plugin does not create this field by default when it is installed, so only sites that added one are exposed.
KEV status: The supplied CISA KEV data contains no entry for this CVE, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor: e4jvikwp
- Product: VikAppointments Services Booking Calendar (WordPress plugin)
- Affected versions: All versions up to and including 1.2.21
- Condition: A File-type custom field is published on the confirmation page shortcode
Patch Status
The NVD record lists all versions up to and including 1.2.21 as affected. It does not name a fixed version. The references include a WordPress plugin Trac changeset, but the supplied data does not say whether that change fixes the flaw.
No CISA KEV required action or due date applies, because there is no KEV entry. Administrators should:
- Check whether any File-type custom fields are published on the confirmation page
- Watch the vendor and Wordfence advisory for a fixed release
- Update as soon as a fixed version is confirmed