CVE-2026-11887
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing an
CVSS
4.3
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jul 1, 2026 · Last modified: Jul 1, 2026
0.2%EPSS · 30 days0.3%
2026-08-082026-09-05
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
No related CVEs by CWE or product.