Wordpresschef · Salon Booking System – Free Version · CVE-2025-8492
**Name of the Vulnerable Software and Affected Versions**
Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses versions prior to 10.23
**Description**
Unauthorized modification of data is possible due to a missing capability check on the ajax function. This allows unauthenticated attackers to execute AJAX actions, which may include limited file uploads.
**Recommendations**
Update the plugin to version 10.23 or later.