A critical unauthenticated SQL injection vulnerability has been identified in the VikAppointments Services Booking Calendar WordPress plugin, affecting versions 1.2.20 and earlier. The vulnerability allows unauthenticated attackers to perform SQL injection attacks without any prior authentication, making it especially dangerous. This type of vulnerability can lead to unauthorized access to sensitive database contents, data exfiltration, and potentially full database compromise. The issue is tracked as CVE-2026-84768 and has been reported via both the National Vulnerability Database and Patchstack. Users of the affected plugin are advised to update to a patched version immediately. The high severity rating reflects the unauthenticated nature of the exploit and the potential for significant data exposure.