CVE-2026-40768: WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object References (IDOR) vulnerability
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Salon booking system Pluginto a version that resolves this vulnerability.Fixed in 10.30.25
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40768?
The severity of CVE-2026-40768 is classified as high with a score of 7.3.
What is CVE-2026-40768?
CVE-2026-40768 is an unauthenticated Insecure Direct Object References (IDOR) vulnerability in versions of the WordPress Salon booking system plugin up to 10.30.24.
How do I fix CVE-2026-40768?
To fix CVE-2026-40768, update the WordPress Salon booking system plugin to the latest version that mitigates the IDOR vulnerability.
What are the potential impacts of CVE-2026-40768?
The potential impacts of CVE-2026-40768 include unauthorized access to sensitive data and actions that can be executed by an unauthenticated user.
Who is affected by CVE-2026-40768?
Users of the WordPress Salon booking system plugin on versions 10.30.24 and below are affected by CVE-2026-40768.