Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure
Strategic Overview
<= 1.6.9.5CVE-2025-11723Vulnerability Overview
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possible for unauthenticated attackers to generate a valid token across sites running the plugin that have not manually set a salt in the wp-config.php file and access booking information that will allow them to make modifications.
Technical Analysis
REMEDIATION: Update to version 1.6.9.6, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C