VYPR

Online Scheduling and Appointment Booking System

by WordPress

CVEs (1)

  • CVE-2026-13395HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL…