Medium severity4.3NVD Advisory· Published Aug 10, 2026· Updated Aug 26, 2026
CVE-2026-17020
CVE-2026-17020
Description
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=10.31.0
Patches
Vulnerability mechanics
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026
- WordPress Plugins: 25 Vulnerabilities Disclosed in Single-Day Batch, Affecting Multiple Core FunctionsVypr Intelligence · Aug 10, 2026