plugin

Aone Sms Vulnerabilities

2 known security issues reported for the Aone Sms WordPress plugin. Most recent disclosed Sep 18, 2025.

1 critical 1 high

Running Aone Sms on your site? Check whether your installed version is affected.

Scan your site free

Service Finder SMS System <= 2.0.0 - Authentication Bypass

high

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.

CVSS:
8.1
Affected:
up to 2.0.0
Fix:
No patched version reported
Disclosed:
Sep 18, 2025

CVE-2025-5955 on NVD →

Service Finder SMS System <= 2.0.0 - Unauthenticated Privilege Escalation

critical

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registration through the aonesms_fn_savedata_after_signup() function. This makes it poss...

CVSS:
9.8
Affected:
up to 2.0.0
Fix:
No patched version reported
Disclosed:
Jul 31, 2025

CVE-2025-5954 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database