Vulnerabilities (CVE)

Filtered by vendor Wpmudev Subscribe
Filtered by product Appointments
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-20206 1 Wpmudev 1 Appointments 2025-12-23 N/A 9.8 CRITICAL
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.