Impact
The vulnerability allows unauthorized parties to retrieve embedded sensitive data from the Salon booking system plugin. The primary impact is a confidentiality compromise without direct integrity or availability effects. The weakness falls under CWE-497, indicating that sensitive information is exposed to users beyond the intended control sphere.
Affected Systems
Affected systems are the WordPress Salon booking system plugin provided by Dimitri Grassi, versions n/a through 10.30.3. No specific build dates are listed beyond the upper bound of 10.30.3.
Risk and Exploitability
The CVSS score of 6.5 marks this as a moderate risk. The EPSS score of less than 1% indicates a low expected exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote, unauthenticated read of plugin data via web requests; however, the exact prerequisites are not detailed in the CVE data, so this inference is tentative.
OpenCVE Enrichment