What is CVE-2026-17021?
CVE-2026-17021: A vulnerability in the Salon Booking System WordPress plugin (through version 10.30.33) allows unauthenticated users to modify the stored total of arbitrary bookings due to improper access restriction on certain AJAX actions and lack of ownership verification. Affected users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-17021: Salon Booking System WordPress plaginində (10.30.33 versiyası daxil olmaqla) autentifikasiya olunmamış istifadəçilərə bəzi AJAX əməliyyatları vasitəsilə rezervasiyaların ümumi məbləğini dəyişməyə imkan verən zəiflik aşkarlanıb. Bu, rezervasiya sahibliyini yoxlamadığı üçün icazəsiz müdaxilələrə səbəb ola bilər. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Salon Booking System plugin are affected by CVE-2026-17021?
This vulnerability affects the Salon Booking System WordPress plugin through version 10.30.33, meaning all versions up to and including 10.30.33 are impacted.
What can an attacker do by exploiting this vulnerability?
An unauthenticated user can modify the stored total of arbitrary bookings via certain AJAX actions due to the lack of ownership verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.