PT-2025-31598 · WordPress · Service Finder Bookings

Friderika Baranyai

·

Published

2025-08-01

·

Updated

2025-08-01

·

CVE-2025-5947

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Service Finder Bookings versions prior to 6.1

Description:

The Service Finder Bookings plugin for WordPress is susceptible to privilege escalation through authentication bypass. This occurs because the plugin does not properly validate a user's cookie value before granting access via the `service finder switch back()` function. This allows unauthenticated attackers to log in as any user, including administrators.

Recommendations:

Disable the plugin and monitor for updates.

Fix

LPE

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-5947

Affected Products

Service Finder Bookings