Access violation vulnerability in Service Finder Bookings 6.0

The Service Finder Bookings plugin for WordPress has a security issue that allows attackers to gain more privileges by taking over someone else’s account. This can happen in all versions of the plugin up to version 6.0. The problem is that the plugin doesn’t check if the person requesting a password change is actually who they say they are. Because of this, people with subscriber access or higher can reset the passwords of other users, even administrators.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.