
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12166 is a blind SQL injection vulnerability in the "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin" for WordPress. It affects all versions up to and including 1.6.9.9, and was published on January 14, 2026. The flaw allows unauthenticated remote attackers to extract sensitive information from the underlying database by appending malicious SQL queries via the order and append_where_sql parameters. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The plugin fails to sufficiently escape user-supplied input in the order and append_where_sql parameters and does not adequately prepare existing SQL queries, enabling attackers to append arbitrary SQL clauses. Because the injection is "blind," data is not returned directly in the HTTP response; instead, attackers infer database contents through boolean-based or time-based techniques. No authentication or user interaction is required, and the attack is conducted entirely over the network (Red Hat CVE, Infinit Sec).
Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, including user credentials, personal data, appointment records, and configuration details. The confidentiality impact is rated High, while integrity and availability are unaffected by this vulnerability alone. However, extracted credentials (e.g., WordPress admin hashes) could enable further compromise, including full site takeover or lateral movement within a hosting environment (Red Hat CVE, Sucuri Blog).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.084%, indicating a relatively low (but non-negligible) probability of active exploitation in the near term. As of the available data, there is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing, though the vulnerability was flagged in CISA's weekly vulnerability bulletin for the week of January 12, 2026. Qualys has published a detection (ID: 530836) for this vulnerability (CISA Bulletin, Qualys).
order or append_where_sql parameters in HTTP requests (typically via GET or POST to the plugin's AJAX or REST API handler).order or append_where_sql parameter, e.g., using boolean-based blind injection: order=id,(CASE WHEN (1=1) THEN id ELSE (SELECT 1 FROM (SELECT SLEEP(5))x) END) or time-based payloads to infer data character by character.sqlmap with the identified parameter to enumerate databases, tables, and extract sensitive data (e.g., WordPress wp_users table for usernames and password hashes): sqlmap -u "https://target.com/wp-admin/admin-ajax.php?action=ssa_booking&order=id" --level=3 --risk=2 --dbms=mysql --dump.wp-admin/admin-ajax.php) or REST API routes associated with the Simply Schedule Appointments plugin, containing encoded or suspicious values in order or append_where_sql parameters; abnormally high request rates from a single IP to booking-related endpoints.SLEEP, UNION, SELECT, CASE WHEN, BENCHMARK) in query parameters; HTTP 200 responses with varying response times suggesting time-based blind injection.wp_users table following exploitation.SLEEP() or complex CASE WHEN expressions originating from the web application user (Infinit Sec).The vendor released a patched version of the Simply Schedule Appointments plugin at version 1.7.0, which addresses the insufficient escaping and SQL preparation issues. WordPress site administrators should update the plugin to version 1.7.0 or later immediately via the WordPress admin dashboard or by downloading the updated plugin from the WordPress plugin repository. As a temporary workaround, restricting access to the vulnerable plugin endpoints via a web application firewall (WAF) rule blocking SQL injection patterns in the order and append_where_sql parameters can reduce exposure (Wordfence, Sucuri Blog).
Wordfence included CVE-2025-12166 in its weekly WordPress vulnerability report for January 12–18, 2026, highlighting it as a notable unauthenticated SQL injection risk (Wordfence). Sucuri also covered it in their January 2026 vulnerability patch roundup (Sucuri Blog). RedPacket Security and The Hacker Wire shared alerts on social media platforms including Bluesky and Mastodon, and CISA referenced it in its weekly vulnerability bulletin (CISA Bulletin). Community reaction has been moderate, consistent with a high-severity but not yet actively exploited WordPress plugin vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."