AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17022

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Salon Booking System plugin for WordPress versions up to 10.30.33 is vulnerable due to inadequate validation of booking ownership tokens, enabling unauthenticated attackers to access and disclose personal information from other customers' booking records by manipulating booking identifiers. Organizations using this plugin should prioritize remediation to protect sensitive customer data and mitigate potential privacy breaches.

CVE
CVE-2026-17022
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.