CyberRota Analysis
AI-GeneratedThe Salon Booking System plugin for WordPress versions up to 10.30.33 is vulnerable due to inadequate validation of booking ownership tokens, enabling unauthenticated attackers to access and disclose personal information from other customers' booking records by manipulating booking identifiers. Organizations using this plugin should prioritize remediation to protect sensitive customer data and mitigate potential privacy breaches.
Original NVD Description
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.