PT-2025-37133 · Wordpresschef+1 · Salon Booking System – Free Version+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses versions prior to 10.23
Description
Unauthorized modification of data is possible due to a missing capability check on the ajax function. This allows unauthenticated attackers to execute AJAX actions, which may include limited file uploads.
Recommendations
Update the plugin to version 10.23 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salon Booking System – Free Version
Salon Booking System