Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Codecheq Devs

#50394of 56,326
5.3Total CVSS
Vulnerabilities · 1
PT-2025-37133
5.3
2025-09-10
Wordpresschef · Salon Booking System – Free Version · CVE-2025-8492
**Name of the Vulnerable Software and Affected Versions** Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses versions prior to 10.23 **Description** Unauthorized modification of data is possible due to a missing capability check on the ajax function. This allows unauthenticated attackers to execute AJAX actions, which may include limited file uploads. **Recommendations** Update the plugin to version 10.23 or later.