PatchSiren cyber security CVE debrief
CVE-2026-17021 Salon Booking System CVE debrief
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. This vulnerability enables attackers to modify booking totals without authorization, potentially leading to financial discrepancies or other security issues. Users should verify the plugin version and restrict access to booking-modification AJAX actions. Additional verification is needed to confirm affected scope and severity. Defenders should review access controls and consider compensating controls for exposed systems while remediation is scheduled and verified.
- Vendor
- Salon Booking System
- Product
- Salon Booking System WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-10
Who should care
Users of the Salon Booking System WordPress plugin, particularly those responsible for managing and securing WordPress installations, should be aware of this vulnerability. Additionally, security teams and vulnerability management teams may need to review and address this issue to ensure the security of their environments. Operators and platform administrators may also need to take action to protect their systems.
Technical summary
The Salon Booking System WordPress plugin through 10.30.33 is vulnerable to unauthorized booking modifications due to insufficient access restrictions and lack of ownership verification for targeted bookings. This allows unauthenticated users to tamper with the stored total of arbitrary bookings. Technical details indicate that the plugin's booking-modification AJAX actions are not properly secured.
Defensive priority
Verify the plugin version and restrict access to booking-modification AJAX actions.
Recommended defensive actions
- Verify the plugin version and restrict access to booking-modification AJAX actions.
- Implement additional access controls and verify ownership of targeted bookings.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The evidence for this CVE is limited. The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. Defenders should verify plugin version and review access controls. Additional verification is needed to confirm affected scope and severity.
Official resources
-
CVE-2026-17021 CVE record
CVE.org
-
CVE-2026-17021 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:49.140Z and has not been modified since then.