Dimitri Grassi Salon Booking System Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the unauthorized retrieval of embedded sensitive data has been identified in the Dimitri Grassi Salon booking system plugin for WordPress, affecting versions through 10.30.3. This issue arises from an exposure of sensitive system information, which could potentially be exploited to access information not typically available to regular users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, which might be used to exploit other weaknesses within the system.

Remediation

Users of the WordPress Salon Booking System plugin should update to version 10.30.4 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jan 22, 2026, 6:07 PM
Updated: Jan 22, 2026, 6:07 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.