WORDPRESS · JULY 2026 · EARLY WARNING

Instant Appointment WordPress Plugin Vulnerability (CVE-2026-15282)

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-15282Severity: CRITICAL

The Instant Appointment plugin for WordPress <=1.2 reportedly has a critical vulnerability allowing arbitrary file uploads, potentially leading to remote code execution.

What happened

The Instant Appointment plugin for WordPress <=1.2 appears to be vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function. This vulnerability is under investigation and may allow unauthenticated attackers to upload arbitrary files, potentially enabling remote code execution on affected sites.

Professional software engineers using the Instant Appointment plugin should assess their exposure to this vulnerability. It is recommended to monitor for updates from the plugin developers and apply any patches as soon as they become available. The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.8.

For more detailed information, consult the primary sources listed, including the NVD entry for CVE-2026-15282. The exact impact and necessary mitigation steps will become clearer as more information is released by the plugin developers and security researchers.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If instant appointment plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats