Privilege Escalation Vulnerability in Service Finder Bookings Plugin for WordPress
CVE-2024-13442
9.8CRITICAL
What is CVE-2024-13442?
The Service Finder Bookings plugin for WordPress is susceptible to privilege escalation, allowing unauthenticated attackers to compromise user accounts. This vulnerability arises from inadequate validation of user identities during actions such as post-booking auto-login and profile updates. An attacker can exploit this flaw to log in as any user if their email address is known, thereby changing passwords and potentially gaining access to sensitive accounts, including those of administrators.
Affected Version(s)
Service Finder Bookings * <= 5.0