CVE-2026-17023
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
- Affected products
- Salon Booking System
- Fix
- Available
- CVSS 3.1
- 4.8 MEDIUM
- EPSS
- 0.2% (7th percentile)
- Weakness
- CWE-284
- NVD status
- Received
- Published
- 2026-08-10
CVE-2026-17023 at NVD
No indexed exploits for CVE-2026-17023 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-17023 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.