Impact
The vulnerability is a missing authorization flaw in the Salon Booking Pro plugin that allows exploitation of incorrectly configured access control security levels. Based on the description, the likely attack vector is a remote attacker interacting with the plugin's web interface; this inference is drawn from the description. Attackers who can interact with the plugin’s web interface could gain unauthorized access to booking data or management functions, compromising data integrity and confidentiality.
Affected Systems
The affected product is the WordPress Salon Booking Pro plugin (salon-booking-plugin-pro-cc) from wordpresschef. All released versions up to and including 10.10.2 are impacted; no specific patch version was provided in the data.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity. An EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely exploitation would occur via a remote attacker interacting with the plugin’s administrative or booking interfaces, taking advantage of the broken access control to perform unauthorized operations.
OpenCVE Enrichment
EUVD