Appointments Plugin for WordPress PHP Object Injection Vulnerability (CVE-2017-20206) — Critical Severity

Overview

The Appointments plugin, a popular tool for scheduling services on WordPress websites, once contained a severe security flaw. This vulnerability, known as PHP Object Injection, allowed malicious actors to gain unauthorized control over affected websites without needing any authentication like a username or password. Attackers actively exploited this by manipulating a specific cookie to secretly inject harmful PHP objects, which often resulted in the creation of backdoors on compromised sites, giving them persistent access.

CVE Details

This critical vulnerability is identified as CVE-2017-20206.

  • Product: WPMU DEV Appointments plugin for WordPress
  • Published Date: October 18, 2025
  • Severity: CRITICAL
  • Status: Analyzed

Affected Products

All versions of the WPMU DEV Appointments plugin for WordPress up to, and including, version 2.2.1 are vulnerable to this PHP Object Injection flaw. If you are running any of these older versions, your website is at significant risk.

Current Status

This vulnerability has been thoroughly analyzed, publicly disclosed, and patches have been released to address the issue. The cybersecurity community has a clear understanding of its nature and impact.

Severity Level

Rated as CRITICAL with a CVSS score of 9.8, this vulnerability poses one of the highest possible risks. Its ease of exploitation by unauthenticated attackers, combined with the potential for complete website compromise and backdoor creation, underscores its severe impact on website security and integrity.

Possible Solutions

The most important action you can take to protect your website from this specific threat is to update the Appointments plugin immediately. Ensure you update to version 2.2.2 or any subsequent version. These updates include the necessary fixes to prevent PHP Object Injection attacks by properly sanitizing and validating cookie data before processing it. Always make it a practice to keep all your WordPress plugins, themes, and core installation updated to their latest versions to safeguard against known vulnerabilities.

References

  • https://plugins.trac.wordpress.org/changeset/1733186/appointments
  • https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/
  • https://www.wordfence.com/threat-intel/vulnerabilities/id/7e8f230e-3f96-4efd-806d-72725b960303?source=cve
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.