First published: Fri Apr 04 2025(Updated: )
Missing Authorization vulnerability in Dimitri Grassi Salon booking system allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon booking system: from n/a through 10.10.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dimitri Grassi Salon Booking System | <=10.10.7 | |
WordPress Salon Booking System | <=10.10.7 | |
Salon Booking System WordPress Plugin | <=10.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32220 has been rated as a high-severity vulnerability due to its potential impact on access control.
To fix CVE-2025-32220, ensure that your Salon booking system or WordPress Salon Booking System plugin is updated to the latest version beyond 10.10.7.
CVE-2025-32220 affects the Dimitri Grassi Salon booking system and the WordPress Salon Booking System plugin up to version 10.10.7.
CVE-2025-32220 allows attackers to exploit incorrectly configured access control security levels to gain unauthorized access.
Yes, immediate action is recommended to patch CVE-2025-32220 to prevent unauthorized access exploitation.