Salon Booking System
cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:wordpress:*:*
- <= 10.20
A vulnerability exists in the Salon Booking System WordPress plugin, specifically in versions through 10.20, due to a lack of proper capability checks on AJAX functions. This flaw allows unauthenticated attackers to execute AJAX actions, potentially leading to unauthorized data modification and limited file uploads.
Exploitation of this vulnerability could result in unauthorized execution of AJAX actions, allowing for data manipulation and restricted file uploads.
The vulnerability can be reproduced by sending an AJAX request to the WordPress site with the 'method' parameter specifying the desired action. Since the plugin does not properly validate the request's authorization, this can be done by an unauthenticated user.
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.