AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17021

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Salon Booking System plugin for WordPress versions up to 10.30.33 is vulnerable due to inadequate access controls on booking-modification AJAX actions, enabling unauthenticated users to manipulate the total of arbitrary bookings. This flaw poses a significant risk of data integrity compromise, potentially leading to financial loss or service disruption. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized booking alterations.

CVE
CVE-2026-17021
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.