CVE-2026-81793: WordPress Salon booking system plugin <= 10.31.9 - Broken Access Control vulnerability
Published Sep 10, 2026
·Updated
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9.
Affected Software
1 affected component
Dimitri Grassi Salon booking system<=10.31.9
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is exploitable without authentication. An attacker can attempt exploitation remotely over the network and does not need user interaction.
2
What impact is indicated by the available severity data?
The CVSS vector indicates low impact to integrity and availability, with no confidentiality impact. The issue is rated medium severity with a score of 6.5.
3
Which plugin versions are affected?
Salon booking system plugin versions up to and including 10.31.5 are identified as affected.