CVE-2026-17022

7.5

WordPress · Salon Booking System

The Salon Booking System WordPress plugin is vulnerable to information exposure, allowing unauthenticated attackers to access sensitive data.

Executive summary

The Salon Booking System WordPress plugin contains an information exposure vulnerability that allows unauthenticated access to sensitive data, posing a high risk to site confidentiality.

Vulnerability

This is an information exposure vulnerability (CWE-200) occurring within the plugin. The attack vector is network based, requires no authentication, and involves no user interaction.

Business impact

Successful exploitation of this vulnerability allows unauthorized actors to access sensitive information managed by the plugin. Given the CVSS score of 7.5, this is a high severity issue that could lead to data breaches, non-compliance with privacy regulations, and significant reputational damage.

Remediation

Immediate Action: Review the official WPScan advisory and update the Salon Booking System plugin to the latest version once a fix is released.

Proactive Monitoring: Monitor server access logs for suspicious requests targeting plugin-specific paths or unusual patterns in data retrieval.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block requests that attempt to access sensitive plugin directories or files.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability represents a significant risk due to its unauthenticated nature and potential for data exposure. Administrators should prioritize monitoring for updates from the vendor and restrict access to the affected plugin functionality until a definitive patch is confirmed and applied.

More WordPress CVEs