216.73.216.36

Attackers Actively Exploiting Critical Vulnerability in Service Finder Bookings Plugin

· Published 09/10/2025 16:54 · Modified 09/10/2025 17:00

Export JSON

Essential information

Published
09/10/2025 16:54
Modified
09/10/2025 17:00
Tags
2025-10-09 authentication bypass exploit service finder service finder bookings vulnerability wordfence wordpress
Related entities
5 observables, 4 techniques (mitre)

Description

On June 8th, 2025, we received a submission through our Bug Bounty Program for an in , a plugin bundled with the theme. This theme has been sold to approximately 6,000 customers. This makes it possible for an unauthenticated attacker to gain access to any account on a site including accounts with the ‘administrator’ role. The vendor released the patched version on July 17, 2025, and we publicly disclosed this on July 31, 2025.

External references