VYPR

Salon Booking System

by Salonbookingsystem

Source repositories

CVEs (22)

  • CVE-2024-2429MedApr 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-4468MedJun 8, 2024
    risk 0.21cvss 4.3epss 0.00

    The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admin_init in all versions up to, and including, 9.9. This makes it possible for authenticated attackers…

Page 2 of 2