Critical severity9.8NVD Advisory· Published Oct 18, 2025· Updated Jun 17, 2026
CVE-2017-20206
CVE-2017-20206
Description
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the wpmudev_appointments cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<=2.2.1+ 1 more
- (no CPE)range: <=2.2.1
- (no CPE)
cpe:2.3:a:wpmudev:appointments:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:wpmudev:appointments:*:*:*:*:*:wordpress:*:*range: <=2.2.1
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/1733186/appointmentsnvdPatch
- www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/nvdPress/Media CoverageThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/7e8f230e-3f96-4efd-806d-72725b960303nvdThird Party Advisory
News mentions
0No linked articles in our index yet.