PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17021 Salon Booking System CVE debrief

The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. This vulnerability enables attackers to modify booking totals without authorization, potentially leading to financial discrepancies or other security issues. Users should verify the plugin version and restrict access to booking-modification AJAX actions. Additional verification is needed to confirm affected scope and severity. Defenders should review access controls and consider compensating controls for exposed systems while remediation is scheduled and verified.

Vendor
Salon Booking System
Product
Salon Booking System WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-10
Advisory published
2026-08-10
Advisory updated
2026-08-10

Who should care

Users of the Salon Booking System WordPress plugin, particularly those responsible for managing and securing WordPress installations, should be aware of this vulnerability. Additionally, security teams and vulnerability management teams may need to review and address this issue to ensure the security of their environments. Operators and platform administrators may also need to take action to protect their systems.

Technical summary

The Salon Booking System WordPress plugin through 10.30.33 is vulnerable to unauthorized booking modifications due to insufficient access restrictions and lack of ownership verification for targeted bookings. This allows unauthenticated users to tamper with the stored total of arbitrary bookings. Technical details indicate that the plugin's booking-modification AJAX actions are not properly secured.

Defensive priority

Verify the plugin version and restrict access to booking-modification AJAX actions.

Recommended defensive actions

  • Verify the plugin version and restrict access to booking-modification AJAX actions.
  • Implement additional access controls and verify ownership of targeted bookings.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The evidence for this CVE is limited. The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. Defenders should verify plugin version and review access controls. Additional verification is needed to confirm affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:49.140Z and has not been modified since then.