CyberRota Analysis
AI-GeneratedThe Salon Booking System plugin for WordPress versions up to 10.30.33 is vulnerable due to insufficient verification of booking ownership on its REST API endpoints. This flaw allows any authenticated user, including those with minimal permissions like Subscribers or self-registered customers, to access and disclose sensitive personal data of other customers, including names, email addresses, and private notes. WordPress site administrators using this plugin should prioritize addressing this vulnerability to protect customer privacy and data integrity.
Original NVD Description
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.