PatchSiren

Salon Booking System CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Salon Booking System CVE published 2026-08-10

CVE-2026-17023

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires t [truncated]

Review Salon Booking System CVE published 2026-08-10

CVE-2026-17022

The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier. This issue arises from inadequate validation of booking ownership tokens, w [truncated]

Review Salon Booking System CVE published 2026-08-10

CVE-2026-17021

The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. This vulnerability enables attackers to modify booking totals without authorization, potentially leading to financial discrep [truncated]

Review Salon Booking System CVE published 2026-08-10

CVE-2026-17020

The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumer [truncated]