Impact
The vulnerability arises from an unrestricted role assignment in the 'nsl_registration_store_extra_input' function of the Service Finder Bookings plugin. Because the function does not verify the user role before creating the account, an attacker can register via the Nextend Social Login integration and choose any role, including Administrator. This results in unauthenticated privilege escalation, allowing the attacker to gain full control over the WordPress site, a flaw consistent with CWE‑266."
Affected Systems
The affected software is the Service Finder Bookings plugin distributed by aonetheme, used by the Service Finder - Directory and Job Board WordPress Theme. All releases up to and including version 5.1 are vulnerable. The issue only manifests when the plugin is used together with the Nextend Social Login plugin, which must be installed and properly configured on the WordPress site."
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of less than 1 % signals a low probability of exploitation at any given time. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it by registering a new user account through the social login flow and specifying an Administrator role, thereby bypassing authentication and gaining full administrative privileges on the site. Because no authentication is required and only the presence of the Nextend Social Login plugin is needed, the risk is high in environments that use this plugin.
OpenCVE Enrichment
EUVD