Vulnerability in Salon Booking System Plugin for WordPress Allows Data Disclosure
CVE-2026-17020

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-17020?

The Salon Booking System plugin for WordPress, up to version 10.30.33, has a serious vulnerability where it fails to verify the ownership of booking requests via its REST API endpoints. This flaw allows any authenticated user, including those with minimal permissions such as Subscribers or self-registered customers, to access and enumerate other users' booking identifiers. Consequently, sensitive customer information such as names, emails, phone numbers, addresses, and private notes can be exposed, posing a significant risk to personal data privacy and security.

Affected Version(s)

Salon Booking System 0 <= 10.30.33

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muni Nitish Kumar Yaddala
WPScan
.