Sploitus

CVE-2026-17020

No indexed exploits for CVE-2026-17020 yet

The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.

Affected products
Salon Booking System
Fix
Available
CVSS 3.1
4.3 MEDIUM
EPSS
0.2% (6th percentile)
Weakness
CWE-639
NVD status
Received
Published
2026-08-10
CVE-2026-17020 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-17020 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-17020 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.