AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17020

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Salon Booking System plugin for WordPress versions up to 10.30.33 is vulnerable due to insufficient verification of booking ownership on its REST API endpoints. This flaw allows any authenticated user, including those with minimal permissions like Subscribers or self-registered customers, to access and disclose sensitive personal data of other customers, including names, email addresses, and private notes. WordPress site administrators using this plugin should prioritize addressing this vulnerability to protect customer privacy and data integrity.

CVE
CVE-2026-17020
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
WordPress

Original NVD Description

The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.