Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticated Sensitive Information Exposure

2026-01-05 15:10
Lucas Montes (NiRoX)

Strategic Overview

Status
Patched in 1.6.9.6
Affected Version<= 1.6.9.5
CVSS6.5Medium
CVECVE-2025-11723
View all Simply Schedule Appointments vulnerabilities

Vulnerability Overview

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possible for unauthenticated attackers to generate a valid token across sites running the plugin that have not manually set a salt in the wp-config.php file and access booking information that will allow them to make modifications.

Technical Analysis

REMEDIATION: Update to version 1.6.9.6, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C