CVE-2026-66453 CRITICAL

CVE-2026-66453: WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability

Vendor Dimitri Grassi
Product Salon booking system
Weakness CWE-288
Published August 13, 2026
Last update August 13, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The Salon booking system contains an authentication bypass vulnerability that allows attackers to gain unauthorized access without valid credentials. An attacker can exploit an alternate authentication path to read, modify, or delete sensitive data and disrupt service availability. No user interaction or special privileges are required. All versions up to 10.30.26 are affected.

What an attacker can do

03Attacker Capabilities

Bypass authentication and gain full access to read, modify, or delete data and disrupt the booking system.

Potential impact on your site

04Site Impact

Attackers can access customer data, bookings, and payment information without a valid account or password.

Conditions required to exploit

05Prerequisites

Network access only; no authentication, special privileges, or user interaction required.

Key dates

06Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

08Related CVE