Description
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access leading to potential data compromise
Action: Patch Now
AI Analysis

Impact

The vulnerability is a CWE‑862 Broken Access Control flaw that allows unauthenticated users to bypass the plugin’s authorization checks. Because the Salon booking system does not verify the requester's privileges, a remote attacker can create, modify, or delete bookings and read sensitive customer data. This can lead to data compromise and potential manipulation of the booking system.

Affected Systems

WordPress sites that have installed the Salon booking system plugin from Dimitri Grassi and are running version 10.31.5 or older. Any site with the vulnerable plugin should verify its installed version and assess exposure.

Risk and Exploitability

The CVSS score of 6.5 indicates moderateSS score is not available, so we cannot quantify exact exploitation probability. The vulnerability is not present in the CISA KEV catalog, implying no documented exploitation. The likely attack path is through unauthenticated HTTP requests to plugin endpoints that lack proper permission checks; attackers only need internet access to the WordPress site to create or modify bookings or view booking details.

Generated by OpenCVE AI on September 10, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the Salon booking system plugin version newer than 10.31.5 to eliminate the broken access control flaw (CWE‑862).
  • Configure WordPress or the web server to restrict access to the plugin’s administrative pages—apply role‑based permission settings or use an .htaccess rule or firewall—so that only authorized users can interact with booking endpoints, mitigating the CWE‑862 weakness.
  • If the plugin is not required for business operations, uninstall or disable it entirely to remove the vulnerability.

Generated by OpenCVE AI on September 10, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Title WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-10T14:23:44.728Z

Reserved: 2026-08-27T12:24:31.287Z

Link: CVE-2026-81793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:45.230

Modified: 2026-09-10T15:43:28.913

Link: CVE-2026-81793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:14Z

Weaknesses