Cross Site Request Forgery in Salon Booking System by WordPress
CVE-2025-47583

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 May 2025

What is CVE-2025-47583?

The Salon Booking System plugin for WordPress is exposed to a significant vulnerability that permits unauthenticated users to initiate Cross Site Request Forgery (CSRF) attacks. This flaw allows attackers to perform actions on behalf of legitimate users without their consent, facilitating potential unauthorized changes and possibly leading to arbitrary content deletion. The affected versions include all releases up to and including 10.16, making it imperative for users to apply the latest security updates to safeguard their installations.

Affected Version(s)

Salon booking system <= 10.16

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NAWardRox (Patchstack Alliance)
.