nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20206 CVE-2017-20206
CRITICAL
Appointments <= 2.2.1 - Unauthenticated PHP Object Injection
Record summary
CVE-2017-20206 has a selected CVSS score of 9.8 (critical).
Description
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 2, 2017 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Appointments Plugin for WordPressBrowse WPMU Dev / Appointments Plugin for WordPress | VulnCheck | Version data not supplied | |
AppointmentsBrowse wpmudev / AppointmentsDefault status: unaffected | CVE List | Before 2.2.2 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/1733186/appointments wordfence.com
https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/7e8f230e-3f96-4efd-806d-72725b960303?source=cve