What is CVE-2026-17022?
A vulnerability in the Salon Booking System WordPress plugin up to version 10.30.33 allows unauthenticated disclosure of booking records. The plugin fails to properly validate ownership tokens in the booking-wizard confirmation steps, enabling attackers to access other customers' bookings and personal information. Update the plugin to the latest version.
Azərbaycanca: Salon Booking System WordPress plugin-də (10.30.33-ə qədər) boşluq aşkarlanıb. Plugin sifariş təsdiqi (booking-wizard) mərhələsində mülkiyyət token-ini düzgün yoxlamır, bu da autentifikasiya olunmamış hücumçulara müştərilərin şəxsi məlumatlarını əhatə edən sifariş qeydlərini əldə etməyə imkan verir. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which WordPress plugin is affected by CVE-2026-17022, and which versions are vulnerable?
The vulnerability affects the Salon Booking System WordPress plugin up to version 10.30.33. Updating the plugin to the latest version is recommended.
What can an unauthenticated attacker gain through the CVE-2026-17022 vulnerability?
An unauthenticated attacker can access booking records containing customers' personal information due to improper validation of ownership tokens in the booking-wizard confirmation steps.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.