What is CVE-2026-17023?
CVE-2026-17023 is a critical vulnerability in the Salon Booking System WordPress plugin up to version 10.30.33, where the Google Calendar authorization callback lacks capability checks and OAuth state validation, allowing unauthenticated attackers to overwrite the site's stored Google Calendar connection. Users should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-17023, Salon Booking System WordPress plugin-inin 10.30.33-ə qədər versiyalarında aşkarlanmış kritik zəiflikdir. Plugin Google Calendar authorization callback-də heç bir capability yoxlaması aparmır və OAuth state dəyərini doğrulamır, bu da autentifikasiya olunmamış hücumçuya saytın Google Calendar bağlantısını ələ keçirməyə imkan verir. İstifadəçilərə dərhal plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: WordPress
FAQ2
Which versions of the Salon Booking System plugin are affected by CVE-2026-17023?
The vulnerability affects the Salon Booking System plugin up to version 10.30.33.
How to protect against CVE-2026-17023?
Users should immediately update the Salon Booking System plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.