CVE-2025-67954: WordPress Salon booking system plugin <= 10.30.3 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67954?
CVE-2025-67954 has been classified as a moderate severity vulnerability due to its potential for exposing sensitive data.
What systems are affected by CVE-2025-67954?
CVE-2025-67954 affects the Dimitri Grassi Salon booking system plugin version 10.30.3 and earlier.
How do I fix CVE-2025-67954?
To fix CVE-2025-67954, you should update the Salon booking system plugin to the latest version available.
What type of vulnerability is CVE-2025-67954?
CVE-2025-67954 is a Sensitive Data Exposure vulnerability that allows unauthorized access to sensitive system information.
Can CVE-2025-67954 be exploited remotely?
Yes, CVE-2025-67954 can potentially be exploited remotely, allowing attackers to retrieve embedded sensitive data.