CVE-2026-66453
9.8Dimitri Grassi · Salon booking system
A critical authentication bypass vulnerability exists in the Dimitri Grassi Salon booking system plugin for WordPress, allowing unauthenticated attackers to gain unauthorized system access.
Executive summary
The Salon booking system plugin is vulnerable to a critical authentication bypass that allows unauthenticated attackers to gain full control over the affected WordPress installation.
Vulnerability
This is an authentication bypass vulnerability (CWE-288) that allows an unauthenticated attacker to circumvent security controls. The vulnerability exists within the plugin logic, enabling unauthorized access without requiring valid credentials.
Business impact
The exploitation of this vulnerability poses a severe risk to the organization, as it grants attackers full administrative access to the WordPress environment. With a CVSS score of 9.8, this flaw could lead to complete data exfiltration, total system compromise, and significant reputational damage if the site is used to distribute malicious content or host phishing pages.
Remediation
Immediate Action: Update the Salon booking system plugin to version 10.30.27 or higher immediately to resolve the authentication flaw.
Proactive Monitoring: Review web server and WordPress application logs for suspicious authentication patterns or unauthorized administrative actions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common authentication bypass patterns or suspicious traffic directed at plugin-specific endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical severity of this vulnerability, administrators must prioritize the update of the Salon booking system plugin to the latest version. Failure to patch allows trivial exploitation by remote attackers, which could result in the total compromise of your web infrastructure.