CVE-2026-17022 PUBLISHED

Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure via Booking Wizard

Assigner: WPScan
Reserved: 24.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.

Product Status

Vendor Unknown
Product Salon Booking System
Versions Default: unknown
  • affected from 0 to 10.30.33 (incl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE