Impact
The vulnerability is a CWE‑862 Broken Access Control flaw that allows unauthenticated users to bypass the plugin’s authorization checks. Because the Salon booking system does not verify the requester's privileges, a remote attacker can create, modify, or delete bookings and read sensitive customer data. This can lead to data compromise and potential manipulation of the booking system.
Affected Systems
WordPress sites that have installed the Salon booking system plugin from Dimitri Grassi and are running version 10.31.5 or older. Any site with the vulnerable plugin should verify its installed version and assess exposure.
Risk and Exploitability
The CVSS score of 6.5 indicates moderateSS score is not available, so we cannot quantify exact exploitation probability. The vulnerability is not present in the CISA KEV catalog, implying no documented exploitation. The likely attack path is through unauthenticated HTTP requests to plugin endpoints that lack proper permission checks; attackers only need internet access to the WordPress site to create or modify bookings or view booking details.
OpenCVE Enrichment