CVE-2025-12166: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12166 is a blind SQL injection vulnerability in the "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin" for WordPress. It affects all versions up to and including 1.6.9.9, and was published on January 14, 2026. The flaw allows unauthenticated remote attackers to extract sensitive information from the underlying database by appending malicious SQL queries via the order and append_where_sql parameters. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The plugin fails to sufficiently escape user-supplied input in the order and append_where_sql parameters and does not adequately prepare existing SQL queries, enabling attackers to append arbitrary SQL clauses. Because the injection is "blind," data is not returned directly in the HTTP response; instead, attackers infer database contents through boolean-based or time-based techniques. No authentication or user interaction is required, and the attack is conducted entirely over the network (Red Hat CVE, Infinit Sec).

Impact

Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, including user credentials, personal data, appointment records, and configuration details. The confidentiality impact is rated High, while integrity and availability are unaffected by this vulnerability alone. However, extracted credentials (e.g., WordPress admin hashes) could enable further compromise, including full site takeover or lateral movement within a hosting environment (Red Hat CVE, Sucuri Blog).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.084%, indicating a relatively low (but non-negligible) probability of active exploitation in the near term. As of the available data, there is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing, though the vulnerability was flagged in CISA's weekly vulnerability bulletin for the week of January 12, 2026. Qualys has published a detection (ID: 530836) for this vulnerability (CISA Bulletin, Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Simply Schedule Appointments plugin version ≤ 1.6.9.9 using tools like WPScan, Shodan, or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Identify vulnerable endpoint: Locate the plugin's booking/calendar endpoint that accepts the order or append_where_sql parameters in HTTP requests (typically via GET or POST to the plugin's AJAX or REST API handler).
  3. Craft blind SQL injection payload: Construct a payload that appends a malicious SQL clause to the order or append_where_sql parameter, e.g., using boolean-based blind injection: order=id,(CASE WHEN (1=1) THEN id ELSE (SELECT 1 FROM (SELECT SLEEP(5))x) END) or time-based payloads to infer data character by character.
  4. Extract database contents: Use automated tools such as sqlmap with the identified parameter to enumerate databases, tables, and extract sensitive data (e.g., WordPress wp_users table for usernames and password hashes): sqlmap -u "https://target.com/wp-admin/admin-ajax.php?action=ssa_booking&order=id" --level=3 --risk=2 --dbms=mysql --dump.
  5. Leverage extracted data: Use cracked password hashes or session tokens to authenticate as an administrator and achieve full site compromise (Infinit Sec, Red Hat CVE).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to WordPress AJAX endpoints (e.g., wp-admin/admin-ajax.php) or REST API routes associated with the Simply Schedule Appointments plugin, containing encoded or suspicious values in order or append_where_sql parameters; abnormally high request rates from a single IP to booking-related endpoints.
  • Logs: WordPress or web server access logs showing requests with SQL keywords (SLEEP, UNION, SELECT, CASE WHEN, BENCHMARK) in query parameters; HTTP 200 responses with varying response times suggesting time-based blind injection.
  • File System: No direct file artifacts expected for a read-only SQL injection, but watch for new admin accounts created in wp_users table following exploitation.
  • Database: Unexpected queries in MySQL slow query logs involving SLEEP() or complex CASE WHEN expressions originating from the web application user (Infinit Sec).

Mitigation and workarounds

The vendor released a patched version of the Simply Schedule Appointments plugin at version 1.7.0, which addresses the insufficient escaping and SQL preparation issues. WordPress site administrators should update the plugin to version 1.7.0 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. As a temporary workaround, restricting access to the vulnerable plugin endpoints via a web application firewall (WAF) rule blocking SQL injection patterns in the order and append_where_sql parameters can reduce exposure (Wordfence, Sucuri Blog).

Community reactions

Wordfence included CVE-2025-12166 in its weekly WordPress vulnerability report for January 12–18, 2026, highlighting it as a notable unauthenticated SQL injection risk (Wordfence). Sucuri also covered it in their January 2026 vulnerability patch roundup (Sucuri Blog). RedPacket Security and The Hacker Wire shared alerts on social media platforms including Bluesky and Mastodon, and CISA referenced it in its weekly vulnerability bulletin (CISA Bulletin). Community reaction has been moderate, consistent with a high-severity but not yet actively exploited WordPress plugin vulnerability.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management