Salon Booking System – Free Version

Information

Software Type Plugin
Software Slug salon-booking-system (view on wordpress.org)
Software Status Active
Software Author wordpresschef
Software Website salonbookingsystem.com
Software Downloads 764,195
Software Active Installs 2,000
Software Record Last Updated July 21, 2026

Showing 1-20 of 31 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter Patched CVE-2026-15070 8.8 Afifudin Maarif July 9, 2026
Salon Booking System – Free Version <= 10.30.25 - Missing Authorization Patched CVE-2026-42666 5.3 Evan NR May 10, 2026
Salon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path Traversal Patched CVE-2026-6320 7.5 daroo May 1, 2026
Salon Booking System – Free Version <= 10.30.24 - Unauthenticated Insecure Direct Object Reference Patched CVE-2026-40768 5.3 Lubin Regnault April 21, 2026
Salon booking system <= 10.30.3 - Authenticated (Subscriber+) Information Exposure Patched CVE-2025-67954 3.1 daroo January 21, 2026
Salon booking system <= 10.30.3 - Cross-Site Request Forgery Patched CVE-2025-66531 4.3 daroo December 7, 2025
Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution Patched CVE-2025-8492 5.3 CodeCheq Devs September 10, 2025
Salon booking system <= 10.16 - Cross-Site Request Forgery to Arbitrary Post/Page Deletion Patched CVE-2025-47583 4.3 NAWardRox May 15, 2025
Salon booking system <= 10.29.6 - Missing Authorization Unpatched CVE-2025-32220 4.3 NAWardRox April 4, 2025
Salon booking system <= 10.11 - Authenticated Privilege Escalation Patched CVE-2025-31560 8.8 Revan Arifio April 1, 2025
Salon booking system <= 10.9 - Authenticated (Subscriber+) Insecure Direct Object Reference Patched CVE-2024-47316 4.3 Sharanabasappa September 25, 2024
Salon Booking System <= 10.9.3 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2024-9882 4.4 Dmitrii Ignatyev September 13, 2024
Salon booking system <= 10.8.1 - Unauthenticated Open Redirect Patched CVE-2024-43280 6.1 Le Ngoc Anh August 16, 2024
Salon booking system <= 10.7 - Authenticated (Administrator+) SQL Injection Patched CVE-2024-39658 9.1 akas wisnu aji August 1, 2024
Salon Booking System <= 10.2 - Unauthenticated Arbitrary File Upload Patched CVE-2024-3229 9.8 Gibran Abdillah June 18, 2024
Salon booking system <= 9.9 - Missing Authorization Patched CVE-2024-4468 4.3 JoanClarke2 June 7, 2024
Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion Patched CVE-2024-4442 9.1 István Márton May 17, 2024
Salon booking system <= 9.6.5 - Cross-Site Request Forgery to Settings Update Patched CVE-2024-2429 4.3 Bob Matyas April 26, 2024
Salon booking system <= 9.6.5 - Authenticated (Editor+) Stored Cross-Site Scripting Patched CVE-2024-2439 4.4 cyc707 April 5, 2024
Salon booking system <= 9.6.5 - Authenticated (Editor+) Stored Cross-Site Scripting via Email Settings Patched CVE-2024-2603 4.4 Bob Matyas April 5, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation