CVE-2025-5949

HIGH

Service Finder Bookings <6.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers with subscriber access or higher to reset other users' passwords, including those of admins.

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
aonetheme/Service Finder Bookings < 6.0
Published Nov 01, 2025
Tracked Since Feb 18, 2026