Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High1
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-09-19

CVE-2025-5955 - Service Finder Sms System Plugin

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.

PLUGIN Service Finder Sms System

CVE-2025-5955

HIGH CVSS 8.1 2025-09-19
Threat Entry Updated 2025-08-04

CVE-2025-5954 - Service Finder Sms System Plugin

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registration through the aonesms_fn_savedata_after_signup() function. This makes it possible for unauthenticated attackers to register as an administrator user.

PLUGIN Service Finder Sms System

CVE-2025-5954

CRITICAL CVSS 9.8 2025-08-01
Scroll to top