CVE-2026-17021
Salon Booking System โ Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
| Vendor | unknown |
| Product | salon booking system |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown salon booking system
Be the first to know when new unknown vulnerabilities affecting unknown salon booking system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Salon Booking System
0 โค 10.30.33
References
Credits
Muni Nitish Kumar Yaddala WPScan