Description
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
Published: 2026-08-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Salon Booking System WordPress plugin, up to version 10.30.33, fails to verify the ownership token of a booking before displaying it in the booking‑wizard confirmation steps. This flaw, a data confidentiality weakness (CWE-200), allows an unauthenticated attacker to supply a sequential booking identifier and retrieve other customers’ booking records, exposing personal information. The vulnerability is a direct confidentiality breach that compromises sensitive booking data.

Affected Systems

The issue affects the Salon Booking System plugin for WordPress, free version 10.30.33 or earlier. No additional vendor or product information is provided.

Risk and Exploitability

The flaw is a data confidentiality breach (CWE-200). An attacker can exploit this flaw simply by accessing the booking‑wizard URLs with a crafted booking ID; no authentication or privileged access is required. Because the flaw is fully reachable through normal site traffic, the exploitation risk is high, with a CVSS score of 7.5 and an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, but it should still be treated with urgency because it exposes personal data.

Generated by OpenCVE AI on August 13, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Salon Booking System plugin to the latest available version that addresses this flaw.
  • If an immediate update is not possible, disable the booking‑wizard functionality or restrict it to authenticated users only—e.g., by implementing role‑based access controls or IP‑based restrictions in WordPress or via .htaccess.
  • Monitor web‑application logs for repeated requests to /booking‑wizard/ URLs with sequential identifiers, and block or throttle suspicious activity using a web‑application firewall or security plugin.
  • Deploy a web‑application firewall rule that detects sequential booking identifiers and blocks or throttles suspicious requests to the /booking‑wizard/ endpoint.

Generated by OpenCVE AI on August 13, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 13 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier. The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
Title Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure via Booking Wizard Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Mon, 10 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress
Vendors & Products Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
Title Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure via Booking Wizard
References

Subscriptions

Salonbookingsystem Salon Booking System
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-13T13:03:21.439Z

Reserved: 2026-07-24T10:19:43.917Z

Link: CVE-2026-17022

cve-icon Vulnrichment

Updated: 2026-08-10T19:09:13.619Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:49.243

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-17022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T18:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor