Unauthorized File Upload Vulnerability Affects Salon Booking System Plugin for WordPress
CVE-2024-3229
What is CVE-2024-3229?
The Salon booking system plugin for WordPress contains a vulnerability that allows arbitrary file uploads. This vulnerability arises from the absence of proper file type validation in the SLN_Action_Ajax_ImportAssistants function. Additionally, due to the insufficient authorization checks in all versions up to and including 10.2, unauthenticated attackers can exploit this flaw to upload arbitrary files to the server hosting the affected site. This exploit poses significant risks, potentially enabling remote code execution and compromising the security of the site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Salon Booking System * <= 10.2
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved