Medium severity5.3NVD Advisory· Published Sep 11, 2025· Updated Jun 17, 2026
CVE-2025-8492
CVE-2025-8492
Description
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated attackers to execute AJAX actions, including limited file uploads.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=10.22+ 1 more
- (no CPE)range: <=10.22
- (no CPE)
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.