CVE · Medium

CVE-2025-11723 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11723 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.6 Use of Insufficiently Random Values Medium 6.5 < 1.6.9.6 1.6.9.6 2026-01-05

CVE-2025-11723

The Simply Schedule Appointments Booking Plugin for WordPress contains a security flaw affecting all versions up to 1.6.9.5, which allows unauthorized parties to obtain sensitive data by exploiting a hardcoded fallback value used in the hash function. This weakness enables attackers to generate valid tokens across multiple sites, potentially leading to unauthorized modifications of booking information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.