Salon Booking System – Appointment Booking for Salons, Barbershops & Spas

Salon Booking System – Appointment Booking for Salons, Barbershops & Spas has 37 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; 34 are fixed and 3 remain unpatched as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 10.0 out of 10. Severity breakdown: 4 critical and 6 high. 2024 was the busiest year with 13 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (22%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

34 of the records (92%) have a vendor fix, while 3 remain unpatched. The oldest unresolved one dates back to 2025.

27 independent researchers contributed these findings, most of them (3) reported by daroo. Salon Booking System – Appointment Booking for Salons, Barbershops & Spas is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891016.04.2015Today21.06.20216.1Salon booking system < 6.3.1 - Stored Cross-Site Scripting CVSS 6.1 · 21.06.202104.03.20226.3Freemius SDK <= 2.4.2 - Missing Authorization Checks CVSS 6.3 · 04.03.202221.03.20225.3Salon Booking System and Salon Booking System Pro <= 7.6.2 - Sensitive Data Disclosure CVSS 5.3 · 21.03.20227.5Salon Booking System and Salon Booking System Pro <= 7.6.2 - Sensitive Information Disclosure CVSS 7.5 · 21.03.202208.11.20226.1Salon booking system <= 7.9 - Reflected Cross-Site Scripting CVSS 6.1 · 08.11.202227.06.20235.4Salon Booking System <= 8.4.6 - Cross-Site Request Forgery to Admin Role Change to Customer, User Meta Update via save_customer CVSS 5.4 · 27.06.202318.07.20236.1Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get CVSS 6.1 · 18.07.202323.11.20237.2Salon booking system < 8.7 - Authenticated (Editor+) Privilege Escalation CVSS 7.2 · 23.11.202327.03.20245.4Salon booking system <= 9.6.2 - Authenticated (Customer+) Stored Cross-Site Scripting CVSS 5.4 · 27.03.20247.2Salon booking system <= 9.6.2 - Unauthenticated Stored Cross-Site Scripting via 'sms_prefix' CVSS 7.2 · 27.03.202428.03.202410.0Salon booking system <= 9.5 - Unauthenticated Arbitrary File Upload CVSS 10.0 · 28.03.202405.04.20244.4Salon booking system <= 9.6.5 - Authenticated (Editor+) Stored Cross-Site Scripting CVSS 4.4 · 05.04.20244.4Salon booking system <= 9.6.5 - Authenticated (Editor+) Stored Cross-Site Scripting via Email Settings CVSS 4.4 · 05.04.202426.04.20244.3Salon booking system <= 9.6.5 - Cross-Site Request Forgery to Settings Update CVSS 4.3 · 26.04.202417.05.20249.1Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 17.05.202407.06.20244.3Salon booking system <= 9.9 - Missing Authorization CVSS 4.3 · 07.06.202418.06.20249.8Salon Booking System <= 10.2 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 18.06.202401.08.20249.1Salon booking system <= 10.7 - Authenticated (Administrator+) SQL Injection CVSS 9.1 · 01.08.202416.08.20246.1Salon booking system <= 10.8.1 - Unauthenticated Open Redirect CVSS 6.1 · 16.08.202413.09.20244.4Salon Booking System <= 10.9.3 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 13.09.202425.09.20244.3Salon booking system <= 10.9 - Authenticated (Subscriber+) Insecure Direct Object Reference CVSS 4.3 · 25.09.202401.04.20258.8Salon booking system <= 10.11 - Authenticated Privilege Escalation CVSS 8.8 · 01.04.202504.04.20254.3Salon booking system <= 10.29.6 - Missing Authorization CVSS 4.3 · 04.04.202515.05.20254.3Salon booking system <= 10.16 - Cross-Site Request Forgery to Arbitrary Post/Page Deletion CVSS 4.3 · 15.05.202510.09.20255.3Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution CVSS 5.3 · 10.09.202507.12.20254.3Salon booking system <= 10.30.3 - Cross-Site Request Forgery CVSS 4.3 · 07.12.202521.01.20263.1Salon booking system <= 10.30.3 - Authenticated (Subscriber+) Information Exposure CVSS 3.1 · 21.01.202621.04.20265.3Salon Booking System – Free Version <= 10.30.24 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 21.04.202601.05.20267.5Salon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path Traversal CVSS 7.5 · 01.05.202610.05.20265.3Salon Booking System – Free Version <= 10.30.25 - Missing Authorization CVSS 5.3 · 10.05.202609.07.20268.8Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter CVSS 8.8 · 09.07.202606.08.20265.3Salon Booking System – Free Version <= 10.30.33 - Missing Authorization to Unauthenticated Google Calendar Connection Hijack CVSS 5.3 · 06.08.20264.3Salon Booking System – Free Version <= 10.31.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Booking PII Disclosure CVSS 4.3 · 06.08.20265.3Salon Booking System – Free Version <= 10.30.33 - Missing Authorization CVSS 5.3 · 06.08.20265.3Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure CVSS 5.3 · 06.08.202607.08.20265.3Salon Booking System – Appointment Booking for Salons, Barbershops & Spas <= 10.30.26 - Missing Authorization CVSS 5.3 · 07.08.202610.08.20264.3Salon Booking System <= 10.30.19 - Missing Authorization to Authenticated (Subscriber+) Booking Approval Bypass CVSS 4.3 · 10.08.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage92%
Open

3

Fixed

34

Get automatic notifications for all Salon Booking System – Appointment Booking for Salons, Barbershops & Spas vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-17023

Salon Booking System – Free Version <= 10.30.33 - Missing Authorization to Unauthenticated Google Calendar Connection Hijack

Read the full analysis

Vulnerability Records

37 records
2026-08-10 00:00CVE-2026-11887
4.3
Medium
KevinYes
2026-08-07 00:00CVE-2026-66453
5.3
Medium
Evan NRYes
2026-08-06 00:00CVE-2026-17023
5.3
Medium
Daniel DhaniswaraNo
2026-08-06 00:00CVE-2026-17020
4.3
Medium
Muni Nitish Kumar YaddalaNo
2026-08-06 00:00CVE-2026-17021
5.3
Medium
Muni Nitish Kumar YaddalaYes
2026-08-06 00:00CVE-2026-17022
5.3
Medium
Usama ArshadYes
2026-07-09 15:29CVE-2026-15070
8.8
High
Afifudin MaarifYes
2026-05-10 00:00CVE-2026-42666
5.3
Medium
Evan NRYes
2026-05-01 21:28CVE-2026-6320
7.5
High
darooYes
2026-04-21 00:00CVE-2026-40768
5.3
Medium
Lubin RegnaultYes
Showing 1–10 of 37 reports
Salon Booking System – Appointment Booking for Salons, Barbershops & Spas banner
Latestv10.31.5

Salon Booking System – Appointment Booking for Salons, Barbershops & Spas

Dimitri Grassi

Author

Dimitri Grassi

4.4(185)
88/100
Last Updated
2026-09-08 (4d ago)
Active Installs
2,000+
Downloads
783,321
Requires WP
6.0+
Requires PHP
7.4.8+
Tested up to
WP 7.0.4
Created
2015-04-16 (12y ago)

The appointment booking plugin built only for salons — not adapted to them. While generic booking plugins try to serve every industry, Salon Booking System is designed around how a salon actually works: staff members with different schedules and skills, services with processing and finishing times, clients who rebook the same treatment every few weeks, and the daily fight against no-shows. Since 2015 it has been the booking system of choice for hairdressers, barbershops, beauty salons, nail studios and spas, with more than 750,000 downloads. Taking bookings in minutes, not in a weekend. Setting up a booking system is where most salons give up. Salon Booking System has an AI Setup Assistant, included in the free version: describe your salon in plain language — opening hours, services, staff members, booking rules — and it fills in the settings for you. You get a booking page your clients can use the same day, and you can still adjust every detail by hand afterwards. Unlimited bookings, services and staff members in the free version — no booking limits, no fee per appointment. See it in action: Online demo | Documentation Built for the way salons work Smart booking form — your clients pick date, service and stylist in seconds, from any device. Customizable steps order, colors, fields and direct booking links for your social profiles. Reduce no-shows — automatic email and SMS reminders and follow-ups (Twilio, Plivo and iP1 supported out of the box). Staff schedules that match reality — individual weekly timetables, holidays, services per staff member, and notifications when they get booked. Salon-specific services — duration, price, categories, conditional “secondary services” (e.g. color + cut), service breaks for processing time, exclusive services. Two-way Google Calendar sync — reservations appear in your Google Calendar; add or cancel appointments from there and the plugin stays in sync. Grow repeat business — customer archive with full booking history, review invitations after the appointment, unlimited discount coupons. Your bookings. Your clients. 0% commission. Unlike marketplace booking apps, Salon Booking System runs on your own WordPress website: You pay no commission on bookings — ever Your client list and booking history belong to you Nobody shows competing salons to your customers Everything included in the free version Back-end calendar Monthly view Weekly view Daily view Assistant view Bookings export Adding/Edit reservations from daily view Block out time slots from daily view General settings Email notifications on new reservation Email notification to selected assistant Email reminder for the customers Email followup Email review notification Email notification custom logo Custom email message to the customers Email message to invite users to leave a review on website or on a custom platform ( Google My Business, Facebook, other.. ) Customisable SMS notification on new reservation SMS notification to selected assistant SMS reminder for the customers SMS followup SMS verification code against spam SMS Alphanumeric ID supported Twilio, Plivo and 1p1sms providers supported by default set you favourite date and time format set when your week starts WordPress Editors as Salon Administrator Availability settings Three bookings methods BASIC / ADVANCED / HIGH END Booking time range Multiple weekly timetable rules Time range validity option for the weekly booking rules Multiple holidays rules Offset between reservations Change booking form steps order ( Date&time – Services – Assistants – Checkout – Payment or reverse ) Manual booking confirmation Users booking cancellation Pause online booking form Repeat past reservations Re-schedule option Payments options Select currency Hide prices Decimals and thousand separators option Check-out options Enable guest checkout Force guest checkout Limit the number of services bookable at the same time Control form fields Log-in with Facebook account Enable Advanced Discount System Custom fields for check-out form Two ways Google Calendar synchronisation Synchronies reservations on salon administrator’s Google Calendar account Salon admin can add and cancel reservations from his Google Calendar account Front-end booking form styling Choose among three different booking form sizes according to your page layout Custom colors palette generator Assistants settings Multiple weekly timetable rules Multiple holidays rules Limit reservations to specific services Multiple reservations for the same slot for classrooms booking Google Calendar synchronisation SMS notification when he’s booked Email notification when he’s booked Services settings Price Duration Unit per session Category grouping Multiple weekly timetable rules No assistant required option Service break Conditional “Secondary services” Direct booking link Exclusive service Hide service on front-end Advanced Discount System Create unlimited coupon codes Create unlimited discounts based on multiple criteria read more.. Customers archive List of customers Details page of each customer with a list of his reservations and feedbacks Customer’s bookings statistics Reports Stats on reservations and revenues Stats on reservations and revenues by services Stats on reservations and revenues by assistant Stats on reservations and revenues by customers Email weekly report Tools Easy import of Users, Services and Assistants and Reservations from a CSV file Frontend pages Booking form page [salon/] Customers account page [salon_booking_my_account] Assistants bookings calendar [salon_booking_calendar] Assistants list [salon_booking_assistant] Services list [salon_booking_services] PRO Edition Features Online Payments ( Stripe or PayPal supported by default ) Deposit Tips Tax calculation Minimum Order Transaction Fee Service price based on selected Assistant Variable duration service Multiple Assistants required for a service Service Lock Service Parallel Execution Booking cloning Resource based reservations Time-zone based on customer location Limit Assistant access priviledge Mobile Web App for Salon Manager and Staff Members Restful API A complete set of API to use Salon Booking System inside your third party applications API DOCS Complete list of PRO Features... Official Add-ons 1-Multi-Shops – Manage multiple branches of your Salon 2-WooCommerce Checkout – Integrate Salon Booking System with Woocommerce checkout 3-Services Packages – Build and Sell Bundled Services 4-Communicator– Send Email Marketing Campaigns to your customers 5-SOAP Notes – Keep track your customers progress 6-Geo Referencing Shops– Prompt the nearest shop to the customer location 7-Geo Referencing Assistants– Prompt the nearest Assistant to the customer location Official Payments Methods Integration Add-ons 1- Takepayments 2- Iyzico 3- Powertranz 4-Cardcom 5-Bancotact 6-Square 7-Paystack 8-Verifone 9-Mollie 10-Viva Wallet 11-Mercado Pago 12-CardConnect 13-Swish 14-Boipa 15-Worldpay 16-RedSys 17-Upay 18-Paytrail 19-PolyPay 20-Wallee 21-Payengine 22-Przelewy24 Official SMS Providers Integration Add-ons 1-OVH 2-SureSMS 3-Spryng 4-SMS Hosting 5-Skebby 6-Capitole Mobile 7-All My SMS 8-SMS to Other Add-ons Mailchimp Integration – Sync your customers list with your Mailchimp audience Third parts integrations Salon Booking System can be integrated with third part platforms trough Zapier.com. Read more..

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C