WordPress Salon Booking System Pro Privilege Escalation Vulnerability
Vulnerability
A privilege escalation vulnerability has been identified in the WordPress Salon Booking System Pro plugin, affecting versions prior to 10.30.12. This vulnerability allows unauthorized users to gain access to actions and privileges that should be reserved for higher-level users, potentially leading to administrative access on the website.
Impact
Exploitation of this vulnerability could allow an attacker to gain administrative privileges on the affected WordPress site, enabling them to perform actions such as modifying content, managing users, and changing site settings.
Remediation
Users of the WordPress Salon Booking System Pro plugin should update to version 10.30.12 or later. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
