CVE-2026-17023: Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Salon Booking System (WordPress plugin)to a version that resolves this vulnerability.Fixed in 10.30.33 - Configuration
Update the plugin so the Google Calendar OAuth callback performs capability checks and validates an OAuth state value, and ensure the callback is not accessible/hooked for unauthenticated users.
Salon Booking System (WordPress plugin) Google Calendar OAuth authorization callback capability/state validation = Enable capability checks and validate the OAuth state value; do not hook the callback for unauthenticated users - Operational
After applying the update/fix, re-authorize the Google Calendar integration to replace any overwritten (hijacked) stored Google OAuth connection tokens with legitimate tokens.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17023?
The severity of CVE-2026-17023 is rated at 62, indicating a moderate risk level.
How do I fix CVE-2026-17023?
To fix CVE-2026-17023, update the Salon Booking System WordPress plugin to version 10.30.34 or later.
What is the impact of CVE-2026-17023 on my WordPress site?
CVE-2026-17023 allows unauthenticated attackers to hijack Google Calendar connections, potentially overwriting stored Google credentials.
Which versions of the Salon Booking System are affected by CVE-2026-17023?
Salon Booking System versions up to and including 10.30.33 are affected by CVE-2026-17023.
Is authentication required to exploit CVE-2026-17023?
No, CVE-2026-17023 can be exploited by unauthenticated users, posing a significant security risk.