The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.

Project Subscriptions

Vendors Products
Salonbookingsystem Subscribe
Salon Booking System Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress
Vendors & Products Salonbookingsystem
Salonbookingsystem salon Booking System
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Title Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T06:00:17.803Z

Reserved: 2026-07-24T10:19:41.896Z

Link: CVE-2026-17021

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T08:00:05Z

Weaknesses

No weakness.