Junglewise Threat Intelligence

CVE-2026-81793: Salon Booking System broken access control vulnerability

CVE-2026-81793 · Severity: medium · CVSS 6.5 · Published 2026-09-10

Technologies: Salon Booking System. Vendors: Salon Booking System.

Executive brief

The Salon Booking System is a WordPress plugin used to manage appointment reservations for salons and service businesses. A flaw in the plugin allows unauthenticated attackers to bypass access controls and view or perform actions on booking records they should not have permission to access, potentially exposing customer data and enabling unauthorized modifications to appointments.

Technical details

The vulnerability is a broken access control flaw in the Salon Booking System WordPress plugin affecting versions up to 10.31.6. The issue allows unauthenticated users to access sensitive pages and perform unauthorized actions on booking data without proper authentication or authorization checks. No authentication is required to exploit this vulnerability, making it accessible over the network. An attacker can view other users' booking information, customer details, and potentially modify or cancel appointments. No official patch is currently available according to the advisory, though updating to a version beyond 10.31.6 (if available) is recommended.

Affected products

  • Salon Booking System Salon Booking System <= 10.31.6

Timeline

  • 2026-09-08: disclosed
  • 2026-09-10: advisory

References

Related threats