CVE-2026-17022
7.5WordPress · Salon Booking System
The Salon Booking System WordPress plugin is vulnerable to information exposure, allowing unauthenticated attackers to access sensitive data.
Executive summary
The Salon Booking System WordPress plugin contains an information exposure vulnerability that allows unauthenticated access to sensitive data, posing a high risk to site confidentiality.
Vulnerability
This is an information exposure vulnerability (CWE-200) occurring within the plugin. The attack vector is network based, requires no authentication, and involves no user interaction.
Business impact
Successful exploitation of this vulnerability allows unauthorized actors to access sensitive information managed by the plugin. Given the CVSS score of 7.5, this is a high severity issue that could lead to data breaches, non-compliance with privacy regulations, and significant reputational damage.
Remediation
Immediate Action: Review the official WPScan advisory and update the Salon Booking System plugin to the latest version once a fix is released.
Proactive Monitoring: Monitor server access logs for suspicious requests targeting plugin-specific paths or unusual patterns in data retrieval.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block requests that attempt to access sensitive plugin directories or files.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability represents a significant risk due to its unauthenticated nature and potential for data exposure. Administrators should prioritize monitoring for updates from the vendor and restrict access to the affected plugin functionality until a definitive patch is confirmed and applied.