PT-2025-11674 · WordPress · Service Finder Bookings

Tonn

·

Published

2025-03-19

·

Updated

2025-03-24

·

CVE-2024-13442

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Service Finder Bookings plugin for WordPress version 5.0 and earlier
Description The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover. This is due to the plugin not properly validating a user's identity prior to performing a post-booking auto-login or updating their profile details, such as the password. This makes it possible for unauthenticated attackers to login as an arbitrary user if their email address is known or change an arbitrary user's password, including administrators, and leverage that to gain access to their account.
Recommendations For versions up to and including 5.0, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the auto-login feature and restricting profile updates to prevent exploitation. Restrict access to profile details, such as the password, to minimize the risk of unauthorized changes. Avoid using the affected plugin until a patched version is available.

Fix

LPE

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13442

Affected Products

Service Finder Bookings