CVE-2025-5954Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registration through the aonesms_fn_savedata_after_signup() function. This makes it possible for unauthenticated attackers to register as an administrator user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-25: 105-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2025-5954 - Critical Privilege Escalation in Service Finder WordPress plugin. Unauthenticated users can register as admin. CVSS 9.8. No patch available. Disable plugin immediately. #CVE #WordPress #infosec #CVEAlert #Developers #sysadmin More CVE +PATCHES: https://www.valtersit.com/cve/CVE-2025-5954/

    Post summary

    The post announces a critical privilege‑escalation flaw (CVE‑2025‑5954) in the Service Finder WordPress plugin, noting no patch yet and advising immediate plugin disablement as a workaround.

    00000234
    904 followersView on X

Explore more