CVE-2026-17020: Unknown Salon Booking System
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
Affected products
- Unknown Salon Booking System: up to and including 10.31.0
Published 2026-08-10. Last modified 2026-08-26.