CVE · Medium

CVE-2025-13754 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13754 Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17 Missing Authorization Medium 5.3 < 1.6.9.17 1.6.9.17 2025-12-18

CVE-2025-13754

The Appointment Booking Calendar plugin has a security flaw in all versions up to 1.6.9.16 that allows unauthorized access to confidential information. This occurs because the plugin's admin embed endpoint is accessible without authentication, revealing sensitive details such as staff and business names, along with configuration data not visible on booking forms. In premium configurations, this vulnerability may also expose API keys for connected services.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.