CVE-2026-17022: Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure via Booking Wizard
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17022?
CVE-2026-17022 has a risk score of 54, indicating a moderate vulnerability.
How do I fix CVE-2026-17022?
To fix CVE-2026-17022, update the Salon Booking System WordPress plugin to the latest version beyond 10.30.33.
What types of information can be disclosed due to CVE-2026-17022?
CVE-2026-17022 can lead to the disclosure of other customers' booking records and personal information.
Who is affected by CVE-2026-17022?
CVE-2026-17022 affects users of the Salon Booking System WordPress plugin version 10.30.33 and earlier.
What is the nature of the vulnerability in CVE-2026-17022?
CVE-2026-17022 is an information leakage vulnerability due to improper validation of booking ownership tokens.