Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 4.5%
from disclosure to weapon70 days
Published on NVDAug 1
1st PoC+70d
VulnCheck+67d
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
aonetheme · Service Finder Bookingspublic PoCs found — 3
githubgithub.com/xxconi/CVE-2025-5947★ 0vulncheckvulncheck.com/xdb/74d09cb20a75unverifiedvulncheckvulncheck.com/xdb/d0d9ac6cd7feunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://themeforest.net/item/service-finder-service-and-business-listing-wordpress-theme/15208793https://www.vicarius.io/vsociety/posts/cve-2025-5947-detect-wordpress-vulnerabilityhttps://www.vicarius.io/vsociety/posts/cve-2025-5947-mitigate-wordpress-vulnerabilityhttps://www.wordfence.com/threat-intel/vulnerabilities/id/c1fe4f60-d93b-4071-90ae-ac863c17fe19?source=cve