PT-2025-38510 · WordPress · Service Finder Sms System

Friderika Baranyai

·

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-5955

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Service Finder SMS System plugin for WordPress versions prior to 2.1.0
Description The Service Finder SMS System plugin for WordPress does not verify a user's phone number before logging them in, leading to authentication bypass. This allows unauthenticated attackers to log in as arbitrary users.
Recommendations Update the Service Finder SMS System plugin to version 2.1.0 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-5955

Affected Products

Service Finder Sms System