CVE-2026-17023
Salon Booking System โ Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
| Vendor | unknown |
| Product | salon booking system |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown salon booking system
Be the first to know when new unknown vulnerabilities affecting unknown salon booking system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Salon Booking System
0 โค 10.30.33
References
Credits
Daniel Dhaniswara WPScan