A popular WordPress theme has a worrying security flaw which could allow full site takeover – here’s what we know




  • CVE-2025-5947 allows unauthenticated admin access in Service Finder WordPress theme versions ≤ 6.0
  • Over 13,800 exploit attempts observed since August; attackers actively target vulnerable sites
  • Patching is critical; blocking five known IPs may help but won’t stop future attacks

Websites running the popular Service Finder Bookings WordPress theme are being actively targeted following the discovery of a critical severity vulnerability.

On July 17, Aonetheme released version 6.1 of Service Finder, which included a fix for an authentication bypass flaw that affected all versions up to, and including, 6.0. Since the plugin did not properly validate a user’s cookie value prior to logging them in, it was possible for unauthenticated attackers to log in as any user – including admin.


https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img