CVE-2026-105070: high-severity vulnerability in Dimitri Grassi Salon booking system
WordPress Salon booking system plugin <= 10.31.7 - Privilege Escalation vulnerability
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Dimitri Grassi · Salon booking systemRelated CVEs — Dimitri Grassi Salon booking system
In the same product, most dangerous first.
CVE-2026-66453CRITICALWordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerabilityEPSS 0.6%CVE-2025-31560HIGHWordPress Salon booking system plugin < 10.15 - Privilege Escalation vulnerabilityEPSS 0.6%CVE-2025-32220MEDIUMWordPress Salon booking system plugin <= 10.31.9 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2025-67954MEDIUMWordPress Salon booking system plugin <= 10.30.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-42666HIGHWordPress Salon booking system plugin <= 10.30.25 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-47316MEDIUMWordPress Salon Booking Wordpress Plugin plugin <= 10.9 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%