Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-17023

Опубликовано: 10 авг. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

EPSS

Процентиль: 7%
0.00171
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.8
github
15 дней назад

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

EPSS

Процентиль: 7%
0.00171
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-284