Access violation vulnerability in Service Finder Bookings 6.0

The Service Finder Bookings plugin for WordPress has a security issue that allows attackers to gain higher privileges without proper authorization. This can happen in all versions, including the latest one (6.0). The problem lies in the plugin not checking the user’s cookie value before logging them in through the service_finder_switch_back() function. This means that anyone, even without an account, can log in as any user, including administrators.

Detected in:

Service Finder Bookings fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.