Description
WordPress Plugin Salon Booking System is prone to multiple information disclosure vulnerabilities. Attackers can exploit these issues to obtain sensitive information that may help in launching further attacks. WordPress Plugin Salon Booking System version 7.6.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 7.6.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:E8F32E0B-4A89-460B-BB78-7C83EF5E16B4
https://sploitus.com/exploit?id=WPEX-ID:5A5AB7A8-BE67-4F70-925C-9CB1EFF2FBE0
https://plugins.trac.wordpress.org/browser/salon-booking-system/trunk/readme.txt?rev=2694854
Related Vulnerabilities
MySQL CVE-2019-2808 Vulnerability (CVE-2019-2808)
WordPress Plugin vSlider Multi Image Slider for WordPress Multiple Vulnerabilities (4.1.2)
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (5.4.17)
WordPress Plugin Events Manager Unspecified Vulnerability (5.5.5)
Oracle Application Server Other Vulnerability (CVE-2005-3449)