๐Ÿ” CVE Alert

CVE-2026-17023

UNKNOWN 0.0

Salon Booking System โ€“ Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

Vendor unknown
Product salon booking system
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown salon booking system

Be the first to know when new unknown vulnerabilities affecting unknown salon booking system are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Salon Booking System
0 โ‰ค 10.30.33

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a116db0a-38ea-43e3-a9cd-991768ce3e07/

Credits

Daniel Dhaniswara WPScan