Critical WordPress Flaw Allows Admin Control via Service Finder Plugin

Critical WordPress Flaw Allows Admin Control via Service Finder Plugin

A critical vulnerability (CVE-2025-5947) in the Service Finder Bookings plugin for WordPress enables unauthenticated attackers to gain administrative access to affected sites. This flaw underscores the urgent need for prompt patching and highlights ongoing risks associated with insecure plugin design.
Oct 12, 2025 CVE: CVE-2025-5947