The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salonbookingsystem
Salonbookingsystem salon Booking System Wordpress Wordpress wordpress |
|
| Vendors & Products |
Salonbookingsystem
Salonbookingsystem salon Booking System Wordpress Wordpress wordpress |
Mon, 10 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. | |
| Title | Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-10T06:00:17.803Z
Reserved: 2026-07-24T10:19:41.896Z
Link: CVE-2026-17021
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T08:00:05Z
Weaknesses
No weakness.