← WordPress Vulnerabilities
WordPress security by component

Salon Booking System – Free Version

Salon Booking System – Free Version manages salon services, staff schedules, appointments, and customer bookings in WordPress.

Salon Booking System – Free Version (salon-booking-system-free-version) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published May 02, 2026; the highest published CVSS base score is 7.5.

Plugin slug: salon-booking-system-free-version

CVE-2026-6320: Salon Booking System – Free Version: Filesystem traversal

Salon Booking System – Free Version is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 10.30.25.

PublishedMay 02, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for salon-booking-system-free-version
Safe version
May 02, 2026 CVE-2026-6320
Salon Booking System – Free Version: Filesystem traversal
Salon Booking System – Free Version is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 10.30.25.
See mitigation notes
CVE7.5
NVDPending