Junglewise Threat Intelligence

CVE-2026-17021: Salon Booking System missing authorization in booking AJAX actions

CVE-2026-17021 · Severity: medium · CVSS 5.3 · Published 2026-08-10

Technologies: Salon Booking System. Vendors: Salon Booking System.

Executive brief

The Salon Booking System WordPress plugin allows unauthenticated attackers to modify booking totals through unprotected booking-modification features. An attacker can inflate or corrupt the recorded cost of any booking by directly calling WordPress AJAX endpoints, enabling them to steal revenue, apply unauthorized discounts, or create financial discrepancies in the business records.

Technical details

The vulnerability is a broken access control (CWE-862) in the plugin's AJAX handlers for booking modifications. The applyTipsAmount and ApplyDiscountCode actions fail to verify user authentication and do not check booking ownership, accepting any attacker-supplied booking ID without authorization checks or CSRF tokens. An unauthenticated attacker can POST directly to wp-admin/admin-ajax.php with parameters like action=salon&method=applyTipsAmount&sln_booking_id=[target]&sln[tips]=[amount] to manipulate stored booking totals. The vulnerability affects versions before 10.30.34; it was patched in 10.30.34. Both the tips handler and discount handler (when the discount system is enabled, which is the default) are exploitable with no authentication, cookie, or nonce required.

Affected products

  • Salon Booking System Salon Booking System before 10.30.34

Timeline

  • 2026-08-06: disclosed
  • 2026-08-10: patched: Fixed in version 10.30.34
  • 2026-08-10: advisory

References

Related threats