CVE-2026-17022
Salon Booking System โ Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
CVSS Score
7.5
EPSS Score
0.3%
EPSS Percentile
17th
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
| Vendor | unknown |
| Product | salon booking system |
| Published | Aug 10, 2026 |
| Last Updated | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown salon booking system
Be the first to know when new high vulnerabilities affecting unknown salon booking system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Salon Booking System
0 < 10.30.34
References
Credits
Usama Arshad WPScan