Description
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Published: 2026-08-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Salon Booking System WordPress plugin, through version 10.30.33, fails to enforce proper access control on several booking‑modification AJAX actions and does not confirm that the user owns the targeted booking. This flaw allows an unauthenticated actor to alter the stored total value of arbitrary bookings. Because the total is a key financial field, such tampering can inflate or deflate revenue figures, compromise data integrity, and potentially lead to audit failures or financial loss.

Affected Systems

This issue affects the WordPress plugin known as Salon Booking System up through version 10.30.33. The vendor is listed only as "Salon Booking System" and no specific fix version is documented in the available data. Any installation of the free plugin prior to 10.30.34 is therefore vulnerable.

Risk and Exploitability

The vulnerable AJAX endpoints are exposed over HTTP or HTTPS and require no authentication, meaning the flaw is directly exploitable by any internet user. The CVSS score of 5.3 and an EPSS score of <1% indicate a medium severity and low likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog, yet the straightforward nature of the access‑control weakness suggests a high impact if used to mass‑tamper booking totals. The likely attack vector is inferred to be unauthenticated AJAX requests invoked from a web browser or script.

Generated by OpenCVE AI on August 13, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Salon Booking System plugin to the latest available version, which should contain the required access‑control fixes.
  • If an update is not immediately possible, disable or restrict the affected AJAX endpoints so that only authenticated administrators can invoke them, for example by configuring web‑server rules or .htaccess settings.
  • Introduce server‑side verification that confirms the current user’s ownership of the booking before allowing any total modification; this can act as a temporary protective measure until a patch is installed.

Generated by OpenCVE AI on August 13, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Title Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress
Vendors & Products Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Title Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering
References

Subscriptions

Salonbookingsystem Salon Booking System
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-13T13:02:28.324Z

Reserved: 2026-07-24T10:19:41.896Z

Link: CVE-2026-17021

cve-icon Vulnrichment

Updated: 2026-08-11T20:54:26.207Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:49.140

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-17021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:15:13Z

Weaknesses