Description
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access leading to potential data compromise
Action: Patch Now
AI Analysis

Impact

The vulnerability is a CWE‑862 Broken Access Control flaw that allows unauthenticated users to bypass the plugin’s authorization checks. Because the Salon booking system does not verify the requester's privileges, a remote attacker can create, modify, or delete bookings and read sensitive customer data. This can lead to data compromise and potential manipulation of the booking system.

Affected Systems

WordPress sites that have installed the Salon booking system plugin from Dimitri Grassi and are running version 10.31.5 or older. Any site with the vulnerable plugin should verify its installed version and assess exposure.

Risk and Exploitability

The CVSS score of 6.5 indicates moderateSS score is not available, so we cannot quantify exact exploitation probability. The vulnerability is not present in the CISA KEV catalog, implying no documented exploitation. The likely attack path is through unauthenticated HTTP requests to plugin endpoints that lack proper permission checks; attackers only need internet access to the WordPress site to create or modify bookings or view booking details.

Generated by OpenCVE AI on September 10, 2026 at 15:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the Salon booking system plugin version newer than 10.31.5 to eliminate the broken access control flaw (CWE‑862).
  • Configure WordPress or the web server to restrict access to the plugin’s administrative pages—apply role‑based permission settings or use an .htaccess rule or firewall—so that only authorized users can interact with booking endpoints, mitigating the CWE‑862 weakness.
  • If the plugin is not required for business operations, uninstall or disable it entirely to remove the vulnerability.

Generated by OpenCVE AI on September 10, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Dimitri Grassi
Dimitri Grassi salon Booking System
Wordpress
Wordpress wordpress
Vendors & Products Dimitri Grassi
Dimitri Grassi salon Booking System
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Title WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Dimitri Grassi Salon Booking System
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T20:19:13.235Z

Reserved: 2026-08-27T12:24:31.287Z

Link: CVE-2026-81793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:45.230

Modified: 2026-09-11T21:17:19.500

Link: CVE-2026-81793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:45:06Z

Weaknesses