PT-2026-69364 · WordPress · Salon Booking System
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Salon Booking System versions prior to 10.30.34
Description
The plugin fails to perform capability checks or validate the OAuth state value during the Google Calendar authorization callback. Because this callback is accessible to unauthenticated users, an attacker can overwrite the stored Google Calendar connection tokens with their own, effectively hijacking the integration. This issue is exploitable only if the site has configured its own Google OAuth client for the calendar feature.
Recommendations
Update the plugin to version 10.30.34 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salon Booking System