Impact
The Service Finder Bookings WordPress plugin is affected by a high‑attacker model in which any user, including admins, can be impersonated. The flaw is a classic example of CWE‑639: an attacker‑controlled cookie value is accepted without proper validation by the service_finder_switch_back() function, causing the system to log the user in automatically.
Affected Systems
All installations of the Service Finder Bookings plugin from aonetheme with version numbers up to and including 6.0 are vulnerable. The issue occurs on any hosting environment or site configuration.
Risk and Exploitability
The CVSS score of 9.8 classifies this issue as a critical vulnerability, and the EPSS score of 4% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but the high severity combined with public disclosure represents a vector is cookie manipulation: an attacker needs to set a crafted user_switch_cookie value in a client browser or via a simple script in order to trigger the unauthorized login. No additional privileges or complex prerequisites are required beyond access to the target domain’s session handling.
OpenCVE Enrichment
EUVD