CVE-2026-11887: CWE-862 Missing Authorization in Salon Booking System
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
AI Analysis
Technical Summary
The Salon Booking System WordPress plugin versions prior to 10.30.20 have a missing authorization vulnerability (CWE-862) in an AJAX action. This flaw permits any authenticated user, regardless of their privilege level, to alter plugin settings and circumvent the manual approval process for new bookings. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting low attack complexity and limited impact on integrity without affecting confidentiality or availability.
Potential Impact
An attacker with any authenticated user account can modify booking system settings and bypass manual approval of new bookings. This could lead to unauthorized bookings being automatically approved, potentially disrupting business operations or enabling fraudulent reservations. There is no impact on confidentiality or availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles and permissions to trusted users only and monitor for suspicious booking activity. Avoid granting unnecessary authenticated access to low-privilege users.
CVE-2026-11887: CWE-862 Missing Authorization in Salon Booking System
Description
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Salon Booking System WordPress plugin versions prior to 10.30.20 have a missing authorization vulnerability (CWE-862) in an AJAX action. This flaw permits any authenticated user, regardless of their privilege level, to alter plugin settings and circumvent the manual approval process for new bookings. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting low attack complexity and limited impact on integrity without affecting confidentiality or availability.
Potential Impact
An attacker with any authenticated user account can modify booking system settings and bypass manual approval of new bookings. This could lead to unauthorized bookings being automatically approved, potentially disrupting business operations or enabling fraudulent reservations. There is no impact on confidentiality or availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles and permissions to trusted users only and monitor for suspicious booking activity. Avoid granting unnecessary authenticated access to low-privilege users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-10T14:21:57.118Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a44f13a27e9c797195bbc5d
Added to database: 07/01/2026, 10:51:38 UTC
Last enriched: 07/08/2026, 13:07:28 UTC
Last updated: 08/14/2026, 12:41:08 UTC
Views: 87
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.