PT-2025-31596 · WordPress · Service Finder Sms System

Friderika Baranyai

·

Published

2025-08-01

·

Updated

2025-08-06

·

CVE-2025-5954

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Service Finder SMS System plugin for WordPress versions prior to 2.0.1
Description The Service Finder SMS System plugin for WordPress is susceptible to privilege escalation, allowing unauthenticated attackers to register as administrator users. This is due to the plugin’s failure to restrict user role selection during registration through the aonesms fn savedata after signup() function.
Recommendations Update to version 2.0.1 or later.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-5954

Affected Products

Service Finder Sms System