Executive brief
The Salon booking system plugin for WordPress, which manages appointments and customer scheduling, contains a security flaw that allows unauthorized individuals to access sensitive information. An attacker could exploit this to view data they should not have permission to see, potentially compromising customer privacy or business operations. This issue affects all versions up to 10.30.25 and can be resolved by updating to the latest version.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Salon booking system plugin for WordPress in versions up to and including 10.30.25. The flaw allows an unauthenticated remote attacker to bypass authorization checks and access sensitive information (Confidentiality: High). The vulnerability stems from a failure to properly validate user permissions or implement sufficient nonce/authentication tokens on specific functions. Attackers can exploit this over the network without any user interaction. A fix is available in version 10.30.26.
Affected products
- Salon booking system Salon booking system <= 10.30.25
Timeline
- 2026-04-10: other: Reported by researcher Evan NR
- 2026-05-10: patched: Version 10.30.26 released
- 2026-06-15: disclosed: NVD publication date