Executive brief
The Salon Booking System WordPress plugin fails to validate OAuth state parameters and authenticate requests in its Google Calendar integration callback, allowing unauthenticated attackers to hijack the site's Google Calendar connection. An attacker can replace the site's stored calendar tokens with their own, severing the legitimate owner's integration and gaining control over the calendar sync feature. This requires the site to have manually configured Google OAuth credentials for the calendar feature.
Technical details
The vulnerability is a broken access control issue (CWE-284) in the Google Calendar OAuth callback handler. The plugin accepts OAuth authorization codes from unauthenticated requests without validating the state parameter or checking user capabilities, and directly exchanges these codes for access tokens using the site's OAuth credentials. An attacker who completes the Google OAuth consent flow with a target site's registered Client ID can supply their resulting authorization code via an unauthenticated GET request to the wp-admin/admin-ajax.php?action=googleoauth-callback endpoint, causing the plugin to store the attacker's tokens site-wide. The vulnerability is fixed in version 10.31.3.
Affected products
- Salon Booking System Salon Booking System through 10.30.33
Timeline
- 2026-08-06: disclosed
- 2026-08-10: patched: Fixed in version 10.31.3