CVE-2026-6320
Salon Booking System – Free Version
Minimum safe version
10.30.26
Update to 10.30.26 or later to address 32 fixable vulnerabilities
Salon Booking System – Free Version <= 10.30.24 - Unauthenticated Insecure Direct Object Reference
Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution
CVE-2025-67954
CVE-2025-66531
CVE-2025-47583
WordPress Salon booking system plugin <= 10.30.23 - Broken Access Control vulnerability
CVE-2025-31560
Salon Booking System <= 10.9.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-47316
CVE-2024-43280
CVE-2024-39658
CVE-2024-37231
CVE-2024-3229
CVE-2024-4468
CVE-2024-4442
CVE-2024-2603
CVE-2024-2439
CVE-2024-2429
CVE-2024-2102
CVE-2024-2101
CVE-2024-30510
CVE-2023-48319
WordPress Salon booking system Plugin <= 8.4.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-3427
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2022-43487
WordPress Plugin "Salon booking system" vulnerable to cross-site scripting
WordPress Salon booking system plugin <= 7.6.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0920
CVE-2022-0919
CVE-2021-24429