Sensitive Information Exposure in Appointment Booking Calendar Plugin for WordPress
CVE-2025-13754
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 December 2025
What is CVE-2025-13754?
The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin for WordPress has a vulnerability that allows unauthorized users to access sensitive information through an exposed admin embed endpoint. This security flaw affects all versions up to and including 1.6.9.16, which exposes private configuration data inadvertently. The endpoint located at /wp-json/ssa/v1/embed-inner-admin provides unauthenticated attackers the ability to gather information like staff names, business names, and non-public configuration settings. When premium versions are configured with integrations, attackers may also obtain sensitive data, including API keys for external services.
Affected Version(s)
Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin * <= 1.6.9.16