More

    A popular WordPress theme has a worrying security flaw which could allow full site takeover – here’s what we know




    • CVE-2025-5947 allows unauthenticated admin access in Service Finder WordPress theme versions ≤ 6.0
    • Over 13,800 exploit attempts observed since August; attackers actively target vulnerable sites
    • Patching is critical; blocking five known IPs may help but won’t stop future attacks

    Websites running the popular Service Finder Bookings WordPress theme are being actively targeted following the discovery of a critical severity vulnerability.

    On July 17, Aonetheme released version 6.1 of Service Finder, which included a fix for an authentication bypass flaw that affected all versions up to, and including, 6.0. Since the plugin did not properly validate a user’s cookie value prior to logging them in, it was possible for unauthenticated attackers to log in as any user – including admin.


    https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img