CVE-2024-43280 MEDIUM

CVE-2024-43280: WordPress Salon Booking System plugin <= 10.8.1 - Open Redirection vulnerability

Vendor Salon Booking System
Product Salon booking system
Weakness CWE-601 · Open redirect
Published August 19, 2024
Last update April 28, 2026

CVSS base score

4.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1.

Explanation of Vulnerability in Simple Terms

02Summary

The Salon Booking System contains an open redirect vulnerability that allows an attacker to redirect users to an external website. An attacker can craft a malicious link that, when clicked by a user, redirects them to a phishing site or other malicious destination. This could be used to steal credentials or distribute malware. The vulnerability requires user interaction to exploit.

What an attacker can do

03Attacker Capabilities

Redirect users to a malicious external website when they click a crafted link.

Potential impact on your site

04Site Impact

Users may be redirected away from your site to phishing or malware sites, damaging trust and potentially exposing credentials.

Conditions required to exploit

05Prerequisites

An attacker needs to trick a user into clicking a malicious link (user interaction required).

Key dates

06Disclosure timeline

August 19, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE