CVE-2026-17021: Unknown Salon Booking System
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Affected products
- Unknown Salon Booking System: before 10.30.34 (fixed in 10.30.34)
Published 2026-08-10. Last modified 2026-08-26.