CVE-2026-17020
N/A
N/A
Summary
The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Salon Booking System | 0 <= 10.30.33 | affected |
Weaknesses
- CWE-639 Authorization Bypass Through User-Controlled Key
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.