The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possible for unauthenticated attackers to generate a valid token across sites running the plugin that have not manually set a salt in the wp-config.php file and access booking information that will allow them to make modifications.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-06 04:15
Updated : 2026-01-08 18:09
NVD link : CVE-2025-11723
Mitre link : CVE-2025-11723
CVE.ORG link : CVE-2025-11723
JSON object : View
Products Affected
No product.
CWE
CWE-330
Use of Insufficiently Random Values
