The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-285 |
Mon, 10 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salonbookingsystem
Salonbookingsystem salon Booking System Wordpress Wordpress wordpress |
|
| Vendors & Products |
Salonbookingsystem
Salonbookingsystem salon Booking System Wordpress Wordpress wordpress |
Mon, 10 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier. | |
| Title | Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure via Booking Wizard | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-10T06:00:17.984Z
Reserved: 2026-07-24T10:19:43.917Z
Link: CVE-2026-17022
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T09:15:03Z