CVE-2025-6574
8.8Aonetheme · Service Finder Bookings
The Service Finder Bookings plugin for WordPress allows authenticated attackers with subscriber-level access to hijack administrator accounts by modifying user email addresses and triggering password resets.
Executive summary
The Service Finder Bookings plugin for WordPress contains a critical privilege escalation vulnerability that allows unauthorized account takeover, posing a severe risk to site integrity.
Vulnerability
This vulnerability, classified as CWE-639, arises from improper validation of user identity during email update operations. It allows any authenticated user, including those with minimal subscriber privileges, to overwrite the email addresses of other users, including administrators, to facilitate unauthorized account access.
Business impact
The ability for a low-privileged attacker to escalate privileges to an administrative level poses a catastrophic risk to the business. A successful exploit grants the attacker full control over the WordPress installation, enabling data exfiltration, the injection of malicious content, or the total compromise of site operations. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent operational disruption.
Remediation
Immediate Action: Update the Service Finder Bookings plugin to version 6.1 or later immediately to apply the necessary identity validation patches.
Proactive Monitoring: Review WordPress user account activity logs for anomalous password reset requests or unauthorized email address changes for administrative accounts.
Compensating Controls: Deploy a Web Application Firewall with rules configured to block suspicious account modification requests, and audit user permissions to ensure strict adherence to the principle of least privilege.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this privilege escalation flaw necessitates an immediate response from all security administrators managing WordPress instances using this plugin. Organizations should prioritize updating to version 6.1 or later to eliminate the underlying authorization bypass. Failure to patch this vulnerability significantly increases the risk of a full-scale account takeover and subsequent compromise of your web infrastructure.
More Aonetheme CVEs
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 6.1 per Wordfence
Sources
Originally found and disclosed by Thái An, per the CVE Program record.