Executive brief
The Salon booking system plugin for WordPress, which manages appointments and customer bookings, contains a security flaw that allows unauthorized individuals to access or modify data. An attacker could exploit this to view sensitive booking information or interfere with the database without needing a password. This could lead to the exposure of customer details or disruption of business operations.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Salon booking system plugin for WordPress (versions <= 10.30.24). The flaw, classified as CWE-639, stems from insufficient authorization checks when accessing internal objects via user-supplied input. A remote, unauthenticated attacker can exploit this by manipulating identifiers in requests to bypass access controls. This may allow the attacker to view sensitive files, access customer booking data, or interact with the database. The issue is resolved in version 10.30.25.
Affected products
- Dimitri Grassi Salon booking system <= 10.30.24
Timeline
- 2026-03-06: disclosed: Reported by Lubin Regnault
- 2026-04-21: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD
- 2026-04-21: patched: Version 10.30.25 released