Access violation vulnerability in Service Finder Bookings 6.0

The Service Finder Bookings plugin for WordPress has a security issue that allows unauthorized access to user accounts. This means that anyone can log in as any user, including administrators, without proper verification. This can be done by using the “claim_business” feature, and it does not require any special privileges or hacking techniques. It is important to note that the attacker needs to know the user’s “claim_id” to take over the admin account, but this can be obtained through brute-forcing.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.