Impact
The Salon Booking System WordPress plugin, up to version 10.30.33, fails to verify the ownership token of a booking before displaying it in the booking‑wizard confirmation steps. This flaw, a data confidentiality weakness (CWE-200), allows an unauthenticated attacker to supply a sequential booking identifier and retrieve other customers’ booking records, exposing personal information. The vulnerability is a direct confidentiality breach that compromises sensitive booking data.
Affected Systems
The issue affects the Salon Booking System plugin for WordPress, free version 10.30.33 or earlier. No additional vendor or product information is provided.
Risk and Exploitability
The flaw is a data confidentiality breach (CWE-200). An attacker can exploit this flaw simply by accessing the booking‑wizard URLs with a crafted booking ID; no authentication or privileged access is required. Because the flaw is fully reachable through normal site traffic, the exploitation risk is high, with a CVSS score of 7.5 and an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, but it should still be treated with urgency because it exposes personal data.
OpenCVE Enrichment