CVE-2026-17023: Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback

Published Aug 10, 2026
·
Updated

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

Affected Software

1 affected component
wordpress/salon-booking-system<=10.30.33

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Salon Booking System (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 10.30.33
  2. Configuration

    Update the plugin so the Google Calendar OAuth callback performs capability checks and validates an OAuth state value, and ensure the callback is not accessible/hooked for unauthenticated users.

    Salon Booking System (WordPress plugin) Google Calendar OAuth authorization callback capability/state validation = Enable capability checks and validate the OAuth state value; do not hook the callback for unauthenticated users
  3. Operational

    After applying the update/fix, re-authorize the Google Calendar integration to replace any overwritten (hijacked) stored Google OAuth connection tokens with legitimate tokens.

Event History

Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-17023?

The severity of CVE-2026-17023 is rated at 62, indicating a moderate risk level.

2

How do I fix CVE-2026-17023?

To fix CVE-2026-17023, update the Salon Booking System WordPress plugin to version 10.30.34 or later.

3

What is the impact of CVE-2026-17023 on my WordPress site?

CVE-2026-17023 allows unauthenticated attackers to hijack Google Calendar connections, potentially overwriting stored Google credentials.

4

Which versions of the Salon Booking System are affected by CVE-2026-17023?

Salon Booking System versions up to and including 10.30.33 are affected by CVE-2026-17023.

5

Is authentication required to exploit CVE-2026-17023?

No, CVE-2026-17023 can be exploited by unauthenticated users, posing a significant security risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203