Unrated severityNVD Advisory· Published Oct 18, 2025· Updated Apr 8, 2026
Appointments <= 2.2.1 - Unauthenticated PHP Object Injection
CVE-2017-20206
Description
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the wpmudev_appointments cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
Affected products
2- Range: <=2.2.1
- wpmudev/Appointmentsv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.