Impact
The Salon Booking System WordPress plugin before version 10.30.20 lacks proper authorization checks on a specific AJAX action (CWE-284) and involves improper permission handling (CWE-732). As a result, any authenticated user, such as a subscriber, can modify the plugin’s approval configuration, bypassing the manual approval requirement for new bookings and compromising the integrity of the booking process.
Affected Systems
WordPress plugin "Salon Booking System" for versions before 10.30.20. No other vendors or product versions are noted.
Risk and Exploitability
The CVSS score is 4.3, reflecting moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated WordPress user who can trigger the vulnerable AJAX endpoint; the attacker can then change the approval setting to allow bookings without manual approval, enabling unauthorized bookings to be accepted.
OpenCVE Enrichment