PT-2025-11674 · WordPress · Service Finder Bookings
Tonn
·
Published
2025-03-19
·
Updated
2025-03-24
·
CVE-2024-13442
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Service Finder Bookings plugin for WordPress version 5.0 and earlier
Description
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover. This is due to the plugin not properly validating a user's identity prior to performing a post-booking auto-login or updating their profile details, such as the
password. This makes it possible for unauthenticated attackers to login as an arbitrary user if their email address is known or change an arbitrary user's password, including administrators, and leverage that to gain access to their account.Recommendations
For versions up to and including 5.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling the auto-login feature and restricting profile updates to prevent exploitation.
Restrict access to profile details, such as the
password, to minimize the risk of unauthorized changes.
Avoid using the affected plugin until a patched version is available.Fix
LPE
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Service Finder Bookings