Impact
The Salon Booking System WordPress plugin, through version 10.30.33, fails to enforce proper access control on several booking‑modification AJAX actions and does not confirm that the user owns the targeted booking. This flaw allows an unauthenticated actor to alter the stored total value of arbitrary bookings. Because the total is a key financial field, such tampering can inflate or deflate revenue figures, compromise data integrity, and potentially lead to audit failures or financial loss.
Affected Systems
This issue affects the WordPress plugin known as Salon Booking System up through version 10.30.33. The vendor is listed only as "Salon Booking System" and no specific fix version is documented in the available data. Any installation of the free plugin prior to 10.30.34 is therefore vulnerable.
Risk and Exploitability
The vulnerable AJAX endpoints are exposed over HTTP or HTTPS and require no authentication, meaning the flaw is directly exploitable by any internet user. The CVSS score of 5.3 and an EPSS score of <1% indicate a medium severity and low likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog, yet the straightforward nature of the access‑control weakness suggests a high impact if used to mass‑tamper booking totals. The likely attack vector is inferred to be unauthenticated AJAX requests invoked from a web browser or script.
OpenCVE Enrichment