PT-2025-31598 · WordPress · Service Finder Bookings

Friderika Baranyai

·

Published

2025-08-01

·

Updated

2025-10-09

·

CVE-2025-5947

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Service Finder Bookings plugin for WordPress versions prior to 6.1
Description The Service Finder Bookings plugin for WordPress has a flaw that allows unauthenticated attackers to escalate privileges and gain administrative access. This is due to improper validation of a user's cookie value before login through the
service finder switch back()
function. Over 13,800 attack attempts have been recorded since August, with over 1,500 daily attacks observed since late September. Attackers can log in as any user, including administrators, without authentication.
Recommendations Update to Service Finder Bookings version 6.1 to mitigate the risk.

Fix

LPE

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-5947

Affected Products

Service Finder Bookings