PoC Index

CVE-2022-0920

HIGH 7.5EPSS 1.5%

The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.45% chance of exploitation in the next 30 days, 72th percentile
Published
2022-04-11
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related