What is CVE-2026-17020?
A vulnerability exists in the Salon Booking System WordPress plugin (up to version 10.30.33) where a REST API endpoint does not verify booking ownership. Any authenticated user, including low-privileged Subscribers, can access and disclose other users' booking information. Site admins should immediately update the plugin to the latest version or harden authentication mechanisms.
Azərbaycanca: WordPress üçün Salon Booking System pluginində (10.30.33-ə qədər versiyalarda) REST API zəifliyi mövcuddur. İstənilən autentifikasiya olunmuş istifadəçi, o cümlədən aşağı səviyyəli "Subscriber" hesabı olan şəxs, başqalarına aid bron məlumatlarını əldə edə bilər. Sayt administratorları plagini dərhal ən son versiyaya yeniləməli və ya autentifikasiya mexanizmlərini sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-17020?
The vulnerability affects all versions of the Salon Booking System WordPress plugin up to version 10.30.33.
What information can be accessed via this vulnerability?
Any authenticated user, including low-privileged Subscribers, can access and disclose other users' booking information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.