Description
The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
* (semver)
Timeline
| 2025-09-18: | Disclosed |
Credits
Friderika Baranyai
References
www.wordfence.com/...-d5cf-4553-b29a-659fe288ece9?source=cve
themeforest.net/...business-listing-wordpress-theme/15208793