By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme
Tech News

Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme

By Viral Trending Content 2 Min Read
Share
SHARE

Oct 09, 2025Ravie LakshmananVulnerability / Website Security

Bypass Authentication in WordPress

Threat actors are actively exploiting a critical security flaw impacting the Service Finder WordPress theme that makes it possible to gain unauthorized access to any account, including administrators, and take control of susceptible sites.

The authentication bypass vulnerability, tracked as CVE-2025-5947 (CVSS score: 9.8), affects the Service Finder Bookings, a WordPress plugin bundled with the Service Finder theme. It was discovered by a researcher who goes by the name Foxyyy.

“This vulnerability makes it possible for an unauthenticated attacker to gain access to any account on a site, including accounts with the ‘administrator’ role,” Wordfence researcher István Márton said.

The problem, at its core, is a case of privilege escalation stemming from authentication bypass due to the plugin not adequately validating a user’s cookie value before logging them in through an account switching function (service_finder_switch_back()).

As a result, an unauthenticated attacker could take advantage of this behavior to sign in to the site as any user, including administrators, effectively hijacking the site and using it for nefarious purposes, such as inserting malicious code to redirect users to fake sites or use it to host malware.

CIS Build Kits

The shortcoming affects all versions of the theme prior to and including 6.0. It was addressed by the plugin maintainers on July 17, 2025, with the release of version 6.1. The theme has been sold to more than 6,100 customers, per data from Envato Market.

The WordPress security company said it has observed exploitation activity targeting CVE-2025-5947 since August 1, 2025, with over 13,800 attempts detected to date. However, the success rate of these efforts is currently not clear.

The following IP addresses have been observed targeting the Service Finder Bookings plugin account switching function –

  • 5.189.221.98
  • 185.109.21.157
  • 192.121.16.196
  • 194.68.32.71
  • 178.125.204.198

Administrators are recommended to audit their sites for any signs of suspicious activity and ensure all the plugins and themes are running the latest version.

You Might Also Like

Inside Intel’s Hail Mary to Reclaim Chip Dominance

Google Search Brings AI Mode to Ireland

Accessibility start-up DevA11y bags €2m to expand team, scale US presence

Meta Display AR Glasses Teardown : Features, Design & Repairability

iPhone 17 Pro Might Shift From Cosmic Orange to Pink

TAGGED: Cyber Security, Cybersecurity, data breach, Internet, Malware, Threat Intelligence, Vulnerability, website security, WordPress
Share This Article
Facebook Twitter Copy Link
Previous Article The Nordic approach to business builds empowerment, team spirit and engagement. But can you copy it? 
Next Article Russia is waging a ‘grey zone campaign’ against Europe, warns von der Leyen
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Who Is Max Ehrich? All About Demi Lovato’s Ex-Fiancé
Celebrity
Clair Obscur: Expedition 33 – Unlimited Resources Would Not Change the Scope of the Game
Gaming News
Inside Intel’s Hail Mary to Reclaim Chip Dominance
Tech News
Shapeshift revives privacy focus with Zcash shielded support
Crypto
Liverpool await official announcement as plans for Manchester United match hit
Sports
Lloyds shares drop on car loan news! Is this a dip-buying opportunity?
Business
Solana Staking ETF Moves Closer To SEC Approval After Key Filing
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Who Is Max Ehrich? All About Demi Lovato’s Ex-Fiancé

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Who Is Max Ehrich? All About Demi Lovato’s Ex-Fiancé
October 9, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?