CVE-2025-32220: WordPress Salon booking system plugin <= 10.30.26 - Broken Access Control vulnerability
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through <= 10.30.23.
Other sources
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through <= 10.30.26.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32220?
CVE-2025-32220 has been rated as a high-severity vulnerability due to its potential impact on access control.
How do I fix CVE-2025-32220?
To fix CVE-2025-32220, ensure that your Salon booking system or WordPress Salon Booking System plugin is updated to the latest version beyond 10.10.7.
What systems are affected by CVE-2025-32220?
CVE-2025-32220 affects the Dimitri Grassi Salon booking system and the WordPress Salon Booking System plugin up to version 10.10.7.
What does CVE-2025-32220 allow an attacker to do?
CVE-2025-32220 allows attackers to exploit incorrectly configured access control security levels to gain unauthorized access.
Is there a need to take immediate action for CVE-2025-32220?
Yes, immediate action is recommended to patch CVE-2025-32220 to prevent unauthorized access exploitation.