Impact
This flaw allows an attacker without credentials to bypass authentication controls in the Salon booking system plugin versions 10.30.26 and older. Due to the broken authentication logic, an attacker might be able to impersonate privileged users, potentially accessing data handled by the plugin. The weakness is identified as an authentication bypass (CWE‑288). The result can lead to unauthorized data disclosure or tampering with plugin‑managed data; the overall effect on the WordPress site depends on how the plugin is used and whether it is properly isolated.
Affected Systems
The affected product is the Salon booking system plugin developed by Dimitri Grassi, used within WordPress installations. All releases up to and including version 10.30.26 are vulnerable; later releases such as 10.30.27 and beyond contain the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. An EPSS score is not available, but the lack of authentication requirements implies that exploitation can be carried out without prior access. Based on the description, it is inferred that attackers could gain unauthorized administrative privileges by sending specific web requests to the plugin’s endpoints. The vulnerability is not listed in CISA’s KEV catalog; nevertheless, if the plugin is in use, the risk remains high. No additional environmental conditions beyond the presence of the vulnerable plugin on a publicly accessible WordPress site appear required.
OpenCVE Enrichment