CVE-2025-5947Active Exploitation

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-05); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-05: 1Mentions · 2026-03-31: 1Active Exploitation · 2026-02-05: 1Technical Details · 2026-02-05: 1Technical Details · 2026-03-31: 102-0503-31
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-051
Active Exploitation1
2026-03-311
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-5947 - critical 🚨 Service Finder Bookings - Authentication Bypass > Service Finder Bookings WordPress plugin <= 6.0 contains a privilege escalation cause... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-5947 @pdnuclei #NucleiTemplates #cve

    Post summary

    A new critical CVE-2025-5947 affects Service Finder Bookings WordPress plugin versions <=6.0, enabling authentication bypass/privilege escalation. No PoC, exploit, or patch details are included.

    00011397
    905 followersView on X
  • ProbablyPwned@probablypwned
    Active Exploitation

    Attackers exploit CVE-2025-5947 in Service Finder Bookings plugin to hijack admin accounts via cookie manipulation, exposing over 6,000 sites. Site owners urged to check plugins immediately. Read more: https://www.probablypwned.com/article/wordpress-service-finder-cve-2025-5947-admin-takeover

    Post summary

    The post reports that CVE-2025-5947 is actively exploited, allowing attackers to hijack admin accounts through cookie manipulation on over 6,000 sites, and urges owners to check the Service Finder Bookings plugin.

    1000046
    16 followersView on X

Explore more