Description
WordPress Plugin Salon Booking System is prone to multiple information disclosure vulnerabilities. Attackers can exploit these issues to obtain sensitive information that may help in launching further attacks. WordPress Plugin Salon Booking System version 7.6.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 7.6.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:E8F32E0B-4A89-460B-BB78-7C83EF5E16B4
https://sploitus.com/exploit?id=WPEX-ID:5A5AB7A8-BE67-4F70-925C-9CB1EFF2FBE0
https://plugins.trac.wordpress.org/browser/salon-booking-system/trunk/readme.txt?rev=2694854
Related Vulnerabilities
WordPress Plugin 10Web Social Post Feed Unspecified Vulnerability (1.1.26)
WordPress Plugin WooCommerce Potential PHP Object Injection (3.4.4)
WordPress Plugin Digg Digg Cross-Site Request Forgery (5.3.4)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-9044)
WordPress Plugin Colorful Categories Cross-Site Request Forgery (2.0.14)