Overview
The Appointments plugin, a popular tool for scheduling services on WordPress websites, once contained a severe security flaw. This vulnerability, known as PHP Object Injection, allowed malicious actors to gain unauthorized control over affected websites without needing any authentication like a username or password. Attackers actively exploited this by manipulating a specific cookie to secretly inject harmful PHP objects, which often resulted in the creation of backdoors on compromised sites, giving them persistent access.
CVE Details
This critical vulnerability is identified as CVE-2017-20206.
- Product: WPMU DEV Appointments plugin for WordPress
- Published Date: October 18, 2025
- Severity: CRITICAL
- Status: Analyzed
Affected Products
All versions of the WPMU DEV Appointments plugin for WordPress up to, and including, version 2.2.1 are vulnerable to this PHP Object Injection flaw. If you are running any of these older versions, your website is at significant risk.
Current Status
This vulnerability has been thoroughly analyzed, publicly disclosed, and patches have been released to address the issue. The cybersecurity community has a clear understanding of its nature and impact.
Severity Level
Rated as CRITICAL with a CVSS score of 9.8, this vulnerability poses one of the highest possible risks. Its ease of exploitation by unauthenticated attackers, combined with the potential for complete website compromise and backdoor creation, underscores its severe impact on website security and integrity.
Possible Solutions
The most important action you can take to protect your website from this specific threat is to update the Appointments plugin immediately. Ensure you update to version 2.2.2 or any subsequent version. These updates include the necessary fixes to prevent PHP Object Injection attacks by properly sanitizing and validating cookie data before processing it. Always make it a practice to keep all your WordPress plugins, themes, and core installation updated to their latest versions to safeguard against known vulnerabilities.
References
- https://plugins.trac.wordpress.org/changeset/1733186/appointments
- https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7e8f230e-3f96-4efd-806d-72725b960303?source=cve


