The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible. This was partially patched in 9.9, and sufficiently patched in 10.0. CVE-2024-37231 appears to be a duplicate of this issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible. | The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible. This was partially patched in 9.9, and sufficiently patched in 10.0. CVE-2024-37231 appears to be a duplicate of this issue. |
| Title | Salon booking system <= 9.8 - Unauthenticated Arbitrary File Deletion | Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion |
| References |
|
Fri, 18 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salonbookingsystem
Salonbookingsystem salon Booking System |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Salonbookingsystem
Salonbookingsystem salon Booking System |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:31:03.779Z
Reserved: 2024-05-02T18:37:46.843Z
Link: CVE-2024-4442
Updated: 2024-08-01T20:40:47.257Z
Status : Modified
Published: 2024-05-21T07:15:08.460
Modified: 2026-04-08T19:21:38.720
Link: CVE-2024-4442
No data.
OpenCVE Enrichment
No data.
Weaknesses