
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Security & Risk Analysis
wordpress.org/plugins/wappointmentGet clients to quickly book a meeting with you by Zoom, GoogleMeet, phone or at your office
Is Appointment Bookings for Zoom GoogleMeet and more – Wappointment Safe to Use in 2026?
Use With Caution
Score 69/100Appointment Bookings for Zoom GoogleMeet and more – Wappointment has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wappointment" plugin, version 2.7.5, exhibits a mixed security posture. On the positive side, the static analysis shows a commendable use of prepared statements for all SQL queries and a reasonably good rate of output escaping. The plugin also implements a healthy number of capability checks. However, a significant concern is the complete absence of nonce checks, which, coupled with the presence of shortcodes, could create opportunities for Cross-Site Request Forgery (CSRF) if user input is not handled with extreme care. The plugin also relies on the Guzzle library, and without information on its version, potential vulnerabilities within this bundled component cannot be ruled out.
The plugin's vulnerability history is a major red flag. With four known CVEs, including one currently unpatched high-severity vulnerability, the plugin has demonstrated a pattern of introducing security flaws. The historical vulnerability types, such as Missing Authorization, Cross-Site Scripting (XSS), and Server-Side Request Forgery (SSRF), are serious and indicate recurring issues in secure coding practices. The recency of the last vulnerability (2025-12-21) suggests that these issues are not historical but recent, making the unpatched high-severity vulnerability particularly alarming.
In conclusion, while "wappointment" v2.7.5 demonstrates some good practices like prepared SQL statements, its significant vulnerability history, the presence of an unpatched high-severity CVE, and the lack of nonce checks pose considerable risks. The potential for CSRF and the history of common web vulnerabilities suggest a need for immediate attention and remediation.
Key Concerns
- Unpatched high severity CVE
- Missing nonce checks
- Bundled library (Guzzle, version unknown)
- 3 medium severity CVEs
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Wappointment <=2.7.2 - Missing Authorization
Wappointment <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.2.4 - Stored Cross-Site Scripting
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Attack Surface
Shortcodes 4
WordPress Hooks 38
Maintenance & Trust
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Maintenance & Trust
Maintenance Signals
Community Trust
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Alternatives
Cal.com
cal-com
Embed Cal.com booking calendar in WordPress.
VikAppointments Services Booking Calendar
vikappointments
A reliable tool for managing any kind of appointments, scheduling the bookings of various services, and organizing the calendars of several employees.
Ultimate Appointment Booking & Scheduling
ultimate-appointment-scheduling
Appointment booking calendar and scheduling plugin that lets you set up different services, service providers, locations and availability
Appointment scheduling and Booking Manager
appointment-scheduling-and-booking-manager
Offer self-service online appointment scheduling by BuddyPress Members, and get more appointments in less time.
3veta Booking Page for WordPress
3veta
3veta Booking Page for WordPress allows you to embed your 3veta booking page to your WordPress website in a simple and easy way.
Appointment Bookings for Zoom GoogleMeet and more – Wappointment Developer Profile
1 plugin · 2K total installs
How We Detect Appointment Bookings for Zoom GoogleMeet and more – Wappointment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wappointment/dist/back-setup.js/wp-content/plugins/wappointment/dist/back.js/wp-content/plugins/wappointment/dist/front.js/wp-content/plugins/wappointment/vendor/autoload.phpwappointment/dist/back-setup.js?ver=wappointment/dist/back.js?ver=wappointment/dist/front.js?ver=HTML / DOM Fingerprints
<!-- todo remove -->