CVE-2026-3658: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3658 is an unauthenticated SQL Injection vulnerability in the "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin" for WordPress. It affects all versions up to and including 1.6.10.0, where insufficient escaping of the fields parameter and lack of proper SQL query preparation allow unauthenticated attackers to extract sensitive data from the database. The vulnerability was published on March 19, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability exists in multiple files within the plugin, including class-td-db-model.php (line 1171), class-td-api-model.php (line 140), and class-appointment-type-model.php (line 907), where user-supplied input via the fields parameter is not properly sanitized or parameterized before being incorporated into SQL queries. An unauthenticated remote attacker can append malicious SQL clauses to existing queries, enabling blind or direct SQL injection without any authentication or user interaction. The fix was introduced in changeset 3485143 of the plugin's SVN repository (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, including usernames, email addresses, and password hashes. While the vulnerability's scope is limited to confidentiality (no integrity or availability impact), compromised password hashes could enable credential cracking and subsequent account takeover, potentially leading to full site compromise if administrator credentials are recovered. The impact is confined to the database of the affected WordPress installation (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.075% (0.000750), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It has been detected by Qualys scanners (detection ID 531160), and the low attack complexity combined with no authentication requirement makes it accessible to a wide range of attackers if targeted (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Simply Schedule Appointments" plugin version ≤ 1.6.10.0 using tools like WPScan, Shodan, or Google dorks targeting plugin-specific paths.
  2. Locate the vulnerable endpoint: Identify the plugin's booking/appointment API endpoint that accepts the fields parameter, which is exposed without authentication.
  3. Craft a malicious SQL payload: Append SQL injection syntax to the fields parameter value (e.g., using UNION-based or time-based blind injection techniques) to manipulate the underlying SQL query.
  4. Extract sensitive data: Use the injected query to enumerate database tables and extract records such as wp_users containing usernames, email addresses, and hashed passwords.
  5. Crack password hashes: Offline crack the extracted WordPress password hashes (typically MD5-based phpass) using tools like Hashcat or John the Ripper to obtain plaintext credentials.
  6. Escalate access: Use recovered administrator credentials to log into the WordPress admin panel and achieve full site control (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual HTTP requests to the plugin's booking API endpoints containing SQL metacharacters (e.g., ', --, UNION, SELECT, SLEEP) in the fields parameter; high volume of requests to appointment booking endpoints from a single IP.
  • Logs: WordPress or web server access logs showing repeated requests with encoded or obfuscated SQL payloads in query strings; anomalous response sizes from booking-related endpoints suggesting data exfiltration.
  • Database: Unexpected or high-frequency queries against wp_users or other sensitive tables originating from the web application process; database error logs showing SQL syntax errors from malformed injection attempts.

Mitigation and workarounds

Users should update the Simply Schedule Appointments plugin to a version beyond 1.6.10.0, as the vulnerability was patched in changeset 3485143. If immediate updating is not possible, consider disabling the plugin until a patch can be applied, or implement a web application firewall (WAF) rule to block requests containing SQL injection patterns in the fields parameter. Regularly audit WordPress plugin versions and apply updates promptly to minimize exposure (Wordfence, WordPress Trac).

Community reactions

Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 16–22, 2026, noting it as a significant unauthenticated SQL injection risk (Wordfence Blog). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). Social media activity was observed on Mastodon and Bluesky, primarily from security aggregator accounts sharing the CVE details, with no notable researcher controversy or debate.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management