CVE-2026-17020
Salon Booking System โ Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure
CVSS Score
4.3
EPSS Score
0.2%
EPSS Percentile
6th
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
| Vendor | unknown |
| Product | salon booking system |
| Published | Aug 10, 2026 |
| Last Updated | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown salon booking system
Be the first to know when new medium vulnerabilities affecting unknown salon booking system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Salon Booking System
0 โค 10.31.0
References
Credits
Muni Nitish Kumar Yaddala WPScan