Impact
The Salon Booking System WordPress plugin through version 10.30.33 fails to perform capability checks or validate the OAuth state value on its Google Calendar authorization callback, which is accessible to unauthenticated users. This flaw allows an attacker without any site credentials to overwrite the stored Google Calendar connection tokens with attacker‑controlled values, thereby hijacking the integration and potentially gaining access to the site’s calendar data. The vulnerability presents a moderate severity (CVSS 4.8) and is classified as CWE‑284 (Improper Authorization).
Affected Systems
The vulnerability affects the Salon Booking System WordPress plugin, version 10.30.33 and earlier. Any WordPress site running this plugin and having configured its own Google OAuth client for calendar functionality is at risk. The vendor is listed as Unknown:Salon Booking System.
Risk and Exploitability
The callback endpoint is available to unauthenticated users and lacks state validation, making the attack path relatively straightforward: an unauthenticated HTTP request to the callback with crafted parameters can overwrite existing tokens. However, the EPSS score of <1% indicates that the likelihood of exploitation in the wild is very low, and the moderate CVSS score of 4.8 denotes a moderate threat if exploited. The vulnerability is not listed in the CISA KEV catalog. Because the flaw does not require additional access or privileged credentials, it is limited to affecting only the Google Calendar integration and does not give full site compromise. The overall risk is moderate, with low exploitation probability.
OpenCVE Enrichment