Impact
The Service Finder SMS System plugin for WordPress allows attackers to gain authentication privileges without providing valid credentials because the plugin fails to validate a user's phone number before logging them in. This flaw enables an unauthenticated adversary to assume the identity of any user, potentially accessing sensitive data, modifying content, or conducting further exploits. The weakness corresponds to CWE-288, which signals improper authorization logic.
Affected Systems
The vulnerability affects the AoneTheme Service Finder SMS System plugin for WordPress in all releases up to and including version 2.0.0. No information is provided about partial mitigation in newer releases, so administrators should assume that earlier versions remain susceptible.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity risk. EPSS is reported as less than 1%, suggesting that while exploitation is possible, the probability of widespread attacks is currently low. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the plugin’s authentication endpoint, which can be triggered by any user with network access to the WordPress site.
OpenCVE Enrichment
EUVD