Service Finder Bookings <= 6.2 - Authenticated (Subscriber+) Privilege Escalation
high
The Service Finder Bookings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
- CVSS:
- 8.8
- Affected:
- up to 6.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 13, 2026
CVE-2026-28161 on NVD →
Service Finder Booking <= 6.2 - Missing Authorization
medium
The Service Finder Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 6.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 13, 2026
CVE-2026-28159 on NVD →
Service Finder Bookings < 6.1 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
high
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 6.1
- Fixed in:
- 6.1
- Disclosed:
- Oct 31, 2025
CVE-2025-6574 on NVD →
Service Finder Bookings <= 6.0 - Authenticated (Subscriber+) Privilege Escalation via change_candidate_password
high
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers wit...
- CVSS:
- 8.8
- Affected:
- up to 6.0
- Fixed in:
- 6.1
- Disclosed:
- Oct 31, 2025
CVE-2025-5949 on NVD →
Service Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_business
critical
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for un...
- CVSS:
- 9.8
- Affected:
- up to 6.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 18, 2025
CVE-2025-5948 on NVD →
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
critical
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it po...
- CVSS:
- 9.8
- Affected:
- up to 6.0
- Fixed in:
- 6.1
- Disclosed:
- Jul 31, 2025
CVE-2025-5947 on NVD →
Service Finder Booking <= 6.0 - Unauthenticated Privilege Escalation
critical
The Service Finder Bookings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 6.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-23970 on NVD →
Service Finder Booking add-on plugin for Service Finder [sf-booking] <= 6.0 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege Escalation. This issue affects Service Finder Booking: from n/a through 6.0.
- Affected:
- up to 6.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-23970 on NVD →
Service Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input'
critical
The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it p...
- CVSS:
- 9.8
- Affected:
- up to 5.1
- Fixed in:
- 6.0
- Disclosed:
- Apr 24, 2025
CVE-2025-2470 on NVD →
Service Finder Booking add-on plugin for Service Finder [sf-booking] < 5.1
unknown
[en] The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is due to the plugin not properly validating a user's identity prior to (1) performing a post-booking auto-login or (2) updating their profile details (e.g. pa...
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Mar 19, 2025
CVE-2024-13442 on NVD →
Service Finder Bookings <= 5.0 - Unauthenticated Privilege Escalation via Account Takeover
critical
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is due to the plugin not properly validating a user's identity prior to (1) performing a post-booking auto-login or (2) updating their profile details (e.g. passwor...
- CVSS:
- 9.8
- Affected:
- up to 5.0
- Fixed in:
- 5.1
- Disclosed:
- Mar 18, 2025
CVE-2024-13442 on NVD →
Service Finder Booking add-on plugin for Service Finder [sf-booking] < 3.2
unknown
Unauthenticated Local File Disclosure vulnerability leading to Local File Inclusion (LFI) found by TELAHDIHAPUS in WordPress Service Finder Booking add-on plugin for Service Finder premium theme (versions <= 3.0).
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- Sep 16, 2020
Service Finder Booking add-on plugin for Service Finder [sf-booking] < 3.2
unknown
The premium Service Finder Booking WordPress plugin was vulnerable to a Local File Disclosure vulnerability that could allow unauthenticated users to include arbitrary files on the server.
- Affected:
- up to 3.2
- Fixed in:
- 3.2
Service Finder Booking add-on plugin for Service Finder [sf-booking] < 6.0
unknown
- Affected:
- up to 6.0
- Fixed in:
- 6.0
CVE-2025-2470 on NVD →
Service Finder Booking add-on plugin for Service Finder [sf-booking] < 6.1
unknown
- Affected:
- up to 6.1
- Fixed in:
- 6.1
CVE-2025-5947 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database