CVE-2025-5947 is a critical authentication bypass vulnerability affecting all versions up to 6.0 of the Service Finder Bookings plugin for WordPress. This flaw allows unauthenticated attackers to log in as any user, including administrators, due to improper cookie validation during the login process. Rated with a CVSS score of 9.8 (Critical), it has a network attack vector and low attack complexity, leading to high impacts on confidentiality, integrity, and availability. The vulnerability is on the "Hot List: Active" and is being actively exploited in the wild, with public proof-of-concept code available and widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Aonetheme | Service Finder Bookings | >= 0, <= 6.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.