Skip to content

Known CVE

Service Finder Bookings - Authentication Bypass

Service Finder Bookings WordPress plugin <= 6.0 contains a privilege escalation caused by improper validation of user cookie in service_finder_switch_back() function, letting unauthenticated attackers login as any user including admins.

CVE-2025-5947

Critical2025CVSS 9.8CWE-639

cve2025 · wordpress · wp-plugin · wp · sf-booking · auth-bypass · cookie-spoofing · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website