Impact
A vulnerability in Service Finder Booking plugin versions up to 6.2 allows an authenticated subscriber to elevate privileges, potentially granting them administrative actions. The flaw is a privilege management error, identified as CWE‑266, which means that the plugin does not correctly enforce role boundaries. If exploited, a subscriber could access or modify data and configuration normally reserved for higher‑level users, leading to unauthorized changes or data exposure.
Affected Systems
The affected component is the WordPress Service Finder Booking plugin from Aonetheme, pre‑version 6.3. Administrators should verify installations of v6.2 or earlier and plan an upgrade.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score is currently unknown. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS and the potential for large‑scale impact mean that it is a serious risk. Attackers would likely need authenticated access as a subscriber; the exact exploitation pathway is not detailed in the description, so it is inferred that the vendor’s internal capability checks are bypassed through normal plugin usage.
OpenCVE Enrichment