Service Finder SMS System <= 2.0.0 - Authentication Bypass
high
The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.
- CVSS:
- 8.1
- Affected:
- up to 2.0.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 18, 2025
CVE-2025-5955 on NVD →
Service Finder SMS System <= 2.0.0 - Unauthenticated Privilege Escalation
critical
The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registration through the aonesms_fn_savedata_after_signup() function. This makes it poss...
- CVSS:
- 9.8
- Affected:
- up to 2.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 31, 2025
CVE-2025-5954 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database