PT-2026-69363 · WordPress · Salon Booking System
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Salon Booking System WordPress plugin versions prior to 10.30.34
Description
The plugin fails to properly validate the ownership token of a booking during the confirmation steps of the booking-wizard. This allows unauthenticated attackers to access and disclose booking records of other customers, including personal information, by providing a sequential booking identifier.
Recommendations
Update the Salon Booking System WordPress plugin to version 10.30.34 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salon Booking System