VYPR

Service Finder Bookings

by WordPress

CVEs (9)

  • CVE-2025-5948CriSep 19, 2025
    risk 0.64cvss 9.8epss 0.00

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business…

  • CVE-2025-5947CriAug 1, 2025
    risk 0.64cvss 9.8epss 0.04

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the…

  • CVE-2025-23970CriJul 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.This issue affects Service Finder Booking: from n/a through <= 6.1.

  • CVE-2025-2470CriApr 25, 2025
    risk 0.64cvss 9.8epss 0.00

    The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the…

  • CVE-2024-13442CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.00

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is due to the plugin not properly validating a user's identity prior to (1) performing a post-booking auto-login or (2)…

  • CVE-2026-28161HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.

  • CVE-2025-6574HigNov 1, 2025
    risk 0.57cvss 8.8epss 0.00

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it…

  • CVE-2025-5949HigNov 1, 2025
    risk 0.57cvss 8.8epss 0.00

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it…

  • CVE-2026-28159MedAug 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.