CVE-2026-17020
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
- Affected products
- Salon Booking System
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.2% (6th percentile)
- Weakness
- CWE-639
- NVD status
- Received
- Published
- 2026-08-10
CVE-2026-17020 at NVD
No indexed exploits for CVE-2026-17020 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-17020 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.