Privilege Escalation Vulnerability in Service Finder Bookings Plugin for WordPress
CVE-2025-2470
What is CVE-2025-2470?
The Service Finder Bookings plugin for WordPress is vulnerable due to insufficient restrictions on user roles within the 'nsl_registration_store_extra_input' function. This oversight allows an unauthenticated attacker to exploit social login functionality to create an account with any role, including Administrator. The vulnerability requires the Nextend Social Login plugin to be installed and properly configured to enable exploitation. This flaw poses severe risks to WordPress sites using the affected versions, as it could lead to unauthorized access and potential site control.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Service Finder Bookings * <= 5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved