Vulnerability in Salon Booking System Plugin for WordPress Allows Data Disclosure
CVE-2026-17020
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
What is CVE-2026-17020?
The Salon Booking System plugin for WordPress, up to version 10.30.33, has a serious vulnerability where it fails to verify the ownership of booking requests via its REST API endpoints. This flaw allows any authenticated user, including those with minimal permissions such as Subscribers or self-registered customers, to access and enumerate other users' booking identifiers. Consequently, sensitive customer information such as names, emails, phone numbers, addresses, and private notes can be exposed, posing a significant risk to personal data privacy and security.
Affected Version(s)
Salon Booking System 0 <= 10.30.33
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.