CVE-2025-66531: WordPress Salon booking system plugin <= 10.30.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Dec 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3.
Affected Software
2 affected components
Dimitri Grassi salon-booking-system<=10.30.3
wordpress/salon-booking-system<=10.30.3
Event History
Dec 9, 2025
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66531?
CVE-2025-66531 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-66531?
To mitigate CVE-2025-66531, upgrade the salon-booking-system to a version later than 10.30.3.
3
What software is affected by CVE-2025-66531?
CVE-2025-66531 affects the Dimitri Grassi salon-booking-system and the WordPress salon-booking-system up to version 10.30.3.
4
What impact does CVE-2025-66531 have on users?
CVE-2025-66531 can allow attackers to perform actions on behalf of authenticated users without their consent.
5
Is there a known exploit for CVE-2025-66531?
At this time, there are no publicly available exploits specifically identified for CVE-2025-66531.