Instant Appointment WordPress Plugin Vulnerability (CVE-2026-15282)
The Instant Appointment plugin for WordPress <=1.2 reportedly has a critical vulnerability allowing arbitrary file uploads, potentially leading to remote code execution.
What happened
The Instant Appointment plugin for WordPress <=1.2 appears to be vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function. This vulnerability is under investigation and may allow unauthenticated attackers to upload arbitrary files, potentially enabling remote code execution on affected sites.
Professional software engineers using the Instant Appointment plugin should assess their exposure to this vulnerability. It is recommended to monitor for updates from the plugin developers and apply any patches as soon as they become available. The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.8.
For more detailed information, consult the primary sources listed, including the NVD entry for CVE-2026-15282. The exact impact and necessary mitigation steps will become clearer as more information is released by the plugin developers and security researchers.
How 0Day mitigates this
instant appointment plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.