CyberRota Analysis
AI-GeneratedThe Salon Booking System plugin for WordPress versions up to 10.30.33 is vulnerable due to inadequate access controls on booking-modification AJAX actions, enabling unauthenticated users to manipulate the total of arbitrary bookings. This flaw poses a significant risk of data integrity compromise, potentially leading to financial loss or service disruption. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized booking alterations.
Original NVD Description
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.