HIGH
Dimitri Grassi
CVE published 2026-06-17
CVE-2026-40768
CVE-2026-40768 is a HIGH-severity vulnerability (CVSS score 7.3) affecting the Salon booking system plugin version 10.30.24 or earlier. The vulnerability is an Unauthenticated Insecure Direct Object References (IDOR) issue, allowing attackers to access sensitive data without authentication. The issue was publicly disclosed on June 17, 2026. Users of the affected plugin should take immediate action to miti [truncated]