{"id":"CVE-2026-17022","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-17022","summary":"The Salon Booking System  WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing…","details":"The Salon Booking System  WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.","published":"2026-08-10T07:16:49.243","modified":"2026-08-10T07:16:49.243","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/ddc84492-408b-477c-ac6c-b9ec96ccf223/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-10T07:16:49.243"}}