PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17021 Salon Booking System CVE debrief

The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. This vulnerability enables attackers to modify booking totals without authorization, potentially leading to financial discrepancies or other security issues. Users should verify the plugin version and restrict access to booking-modification AJAX actions. Additional verification is needed to confirm affected scope and severity. Defenders should review access controls and consider compensating controls for exposed systems while remediation is scheduled and verified.

Vendor
Salon Booking System
Product
Salon Booking System WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-26
Advisory published
2026-08-10
Advisory updated
2026-08-26

Who should care

Users of the Salon Booking System WordPress plugin, particularly those responsible for managing and securing WordPress installations, should be aware of this vulnerability. Additionally, security teams and vulnerability management teams may need to review and address this issue to ensure the security of their environments. Operators and platform administrators may also need to take action to protect their systems.

Technical summary

The Salon Booking System WordPress plugin through 10.30.33 is vulnerable to unauthorized booking modifications due to insufficient access restrictions and lack of ownership verification for targeted bookings. This allows unauthenticated users to tamper with the stored total of arbitrary bookings. Technical details indicate that the plugin's booking-modification AJAX actions are not properly secured.

Defensive priority

Verify the plugin version and restrict access to booking-modification AJAX actions.

Recommended defensive actions

  • Verify the plugin version and restrict access to booking-modification AJAX actions.
  • Implement additional access controls and verify ownership of targeted bookings.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The evidence for this CVE is limited. The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. Defenders should verify plugin version and review access controls. Additional verification is needed to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17021 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17021

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17021 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17021

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.