Description
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
Published: 2026-08-10
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Salon Booking System WordPress plugin through version 10.30.33 fails to perform capability checks or validate the OAuth state value on its Google Calendar authorization callback, which is accessible to unauthenticated users. This flaw allows an attacker without any site credentials to overwrite the stored Google Calendar connection tokens with attacker‑controlled values, thereby hijacking the integration and potentially gaining access to the site’s calendar data. The vulnerability presents a moderate severity (CVSS 4.8) and is classified as CWE‑284 (Improper Authorization).

Affected Systems

The vulnerability affects the Salon Booking System WordPress plugin, version 10.30.33 and earlier. Any WordPress site running this plugin and having configured its own Google OAuth client for calendar functionality is at risk. The vendor is listed as Unknown:Salon Booking System.

Risk and Exploitability

The callback endpoint is available to unauthenticated users and lacks state validation, making the attack path relatively straightforward: an unauthenticated HTTP request to the callback with crafted parameters can overwrite existing tokens. However, the EPSS score of <1% indicates that the likelihood of exploitation in the wild is very low, and the moderate CVSS score of 4.8 denotes a moderate threat if exploited. The vulnerability is not listed in the CISA KEV catalog. Because the flaw does not require additional access or privileged credentials, it is limited to affecting only the Google Calendar integration and does not give full site compromise. The overall risk is moderate, with low exploitation probability.

Generated by OpenCVE AI on August 13, 2026 at 11:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Salon Booking System plugin to a version newer than 10.30.33 when a patch is released.
  • Revoke all existing Google OAuth tokens for the site and force re‑authentication to invalidate any attacker‑controlled tokens.
  • Disable the Google Calendar integration on the site until a verified patch is applied to eliminate the vulnerable callback endpoint.
  • Monitor web server logs for unexpected POST requests to the OAuth callback URL and investigate any suspicious activity.

Generated by OpenCVE AI on August 13, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress
Weaknesses CWE-20
CWE-284
Vendors & Products Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
Title Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
References

Subscriptions

Salonbookingsystem Salon Booking System
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-11T20:55:17.873Z

Reserved: 2026-07-24T10:19:45.313Z

Link: CVE-2026-17023

cve-icon Vulnrichment

Updated: 2026-08-11T20:55:12.679Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:49.353

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-17023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:30:16Z

Weaknesses