Sensitive Information Exposure in Appointment Booking Calendar Plugin for WordPress
CVE-2025-13754

5.3MEDIUM

What is CVE-2025-13754?

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin for WordPress has a vulnerability that allows unauthorized users to access sensitive information through an exposed admin embed endpoint. This security flaw affects all versions up to and including 1.6.9.16, which exposes private configuration data inadvertently. The endpoint located at /wp-json/ssa/v1/embed-inner-admin provides unauthenticated attackers the ability to gather information like staff names, business names, and non-public configuration settings. When premium versions are configured with integrations, attackers may also obtain sensitive data, including API keys for external services.

Affected Version(s)

Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin * <= 1.6.9.16

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcin Dudek
.
CVE-2025-13754 : Sensitive Information Exposure in Appointment Booking Calendar Plugin for WordPress