CVE-2025-47583: WordPress Salon booking system plugin <= 10.16 - CSRF to Arbitrary Content Deletion vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16.
Other sources
Unauthenticated Cross Site Request Forgery (CSRF) in Salon booking system <= 10.16 versions.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47583?
CVE-2025-47583 is classified as a high severity vulnerability due to its potential for unauthorized actions through unauthenticated Cross Site Request Forgery (CSRF).
How do I fix CVE-2025-47583?
To fix CVE-2025-47583, update the Salon booking system or the WordPress Salon booking system plugin to version 10.17 or later.
Who is affected by CVE-2025-47583?
CVE-2025-47583 affects users of the Salon booking system and WordPress Salon booking system plugin versions 10.16 and below.
What type of vulnerability is CVE-2025-47583?
CVE-2025-47583 is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability.
Can CVE-2025-47583 lead to data loss?
Yes, CVE-2025-47583 can lead to arbitrary content deletion, potentially resulting in data loss.