Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

At Starbase, SpaceX is doing its own firefighting.

Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

FleetWorks raises $17 million to match truck drivers with freight faster

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Critical exploit allows hackers to bypass authentication in WordPress Service Finder themes
Identity

Critical exploit allows hackers to bypass authentication in WordPress Service Finder themes

userBy userOctober 9, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 9, 2025Ravi LakshmananVulnerabilities / Website Security

Bypassing authentication in WordPress

Threat actors are actively exploiting a critical security flaw affecting the Service Finder WordPress theme that allows them to gain unauthorized access to any account, including administrators, and take control of susceptible sites.

The authentication bypass vulnerability, tracked as CVE-2025-5947 (CVSS score: 9.8), affects Service Finder Bookings, a WordPress plugin bundled with the Service Finder theme. It was discovered by a researcher named Foxyyy.

“This vulnerability allows an unauthenticated attacker to gain access to any account on the site, including accounts with the ‘admin’ role,” said Wordfence researcher Istvan Marton.

At the core of this issue is a case of privilege escalation due to authentication bypass, as the plugin does not properly validate the user’s cookie value before logging in through the account switch functionality (service_finder_switch_back()).

As a result, an unauthenticated attacker could take advantage of this behavior by signing in to a site as any user, including an administrator, effectively taking over the site and using it for illicit purposes, such as injecting malicious code to redirect users to a fake site or using the site to host malware.

CIS build kit

This drawback affects all versions of the theme prior to 6.0. This issue was addressed by the plugin administrator on July 17, 2025 with the release of version 6.1. According to Envato Market data, this theme has been sold to over 6,100 customers.

The WordPress security firm said it has been observing exploit activity targeting CVE-2025-5947 since August 1, 2025, and has detected over 13,800 attempts to date. However, the success rate of these efforts is currently unclear.

The following IP addresses have been observed targeting the account switching functionality of the Service Finder Bookings plugin –

5.189.221.98 185.109.21.157 192.121.16.196 194.68.32.71 178.125.204.198

We recommend that administrators audit their sites for signs of suspicious activity and ensure that all plugins and themes are running the latest versions.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHistory of Science: The first two-way telephone over an outdoor line by Alexander Graham Bell — October 9, 1876
Next Article OpenAI’s affordable ChatGPT Go plan expands to 16 new countries in Asia
user
  • Website

Related Posts

Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

October 14, 2025

How Threat Hunting Builds Readiness

October 14, 2025

A single 8-byte write shatters AMD’s SEV-SNP Confidential Computing security

October 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

At Starbase, SpaceX is doing its own firefighting.

Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

FleetWorks raises $17 million to match truck drivers with freight faster

Aquawise unveils AI-powered water quality technology at TechCrunch Disrupt 2025

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Beyond the Algorithm: How FySelf’s TwinH and Reinforcement Learning are Reshaping Future Education

Meet Your Digital Double: FySelf Unveils TwinH, the Future of Personalized Online Identity

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.