Description
WordPress Plugin Salon Booking System is prone to multiple information disclosure vulnerabilities. Attackers can exploit these issues to obtain sensitive information that may help in launching further attacks. WordPress Plugin Salon Booking System version 7.6.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 7.6.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:E8F32E0B-4A89-460B-BB78-7C83EF5E16B4
https://sploitus.com/exploit?id=WPEX-ID:5A5AB7A8-BE67-4F70-925C-9CB1EFF2FBE0
https://plugins.trac.wordpress.org/browser/salon-booking-system/trunk/readme.txt?rev=2694854
Related Vulnerabilities
Drupal Core 7.x Cross-Site Scripting (7.0 - 7.79)
WordPress Plugin My Tickets Cross-Site Scripting (1.8.30)
WordPress Plugin Comment Attachment Cross-Site Scripting (1.5.5)
WordPress Plugin WP Editor Arbitrary File Upload (1.2.5.3)
WordPress Plugin Easy PayPal Buy Now Button Cross-Site Scripting (1.7.3)