CVE-2026-28161
8.8Aonetheme · Service Finder Booking
A privilege escalation vulnerability in the Aonetheme Service Finder Booking WordPress plugin allows authenticated subscribers to elevate their privileges to higher roles.
Executive summary
A vulnerability in the Service Finder Booking plugin for WordPress allows authenticated subscribers to perform unauthorized privilege escalation, posing a significant risk of full system compromise.
Vulnerability
This vulnerability is caused by an incorrect privilege assignment (CWE-266), which permits authenticated users with low-level subscriber access to perform administrative actions or escalate their account privileges.
Business impact
The ability for a subscriber to escalate privileges can lead to total system compromise, unauthorized data exfiltration, and the modification of critical booking information. With a CVSS score of 8.8, this high-severity flaw represents a major threat to the integrity and confidentiality of the platform.
Remediation
Immediate Action: Administrators should verify if their plugin version is 6.2 or lower and monitor vendor communications for a security patch. If no patch is currently available, disable the plugin to prevent exploitation.
Proactive Monitoring: Review WordPress user account logs for suspicious account role changes and monitor for unusual administrative activity originating from low-privileged accounts.
Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block malicious requests attempting to invoke administrative functions by low-privileged users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity and the potential for complete control over the WordPress site, immediate action is required. Organizations using the Service Finder Booking plugin must audit their current installations and restrict access until a vendor-supplied patch is successfully deployed.