Hackers exploit auth bypass in Service Finder WordPress theme
ID: 523ea9d2-367e-5184-a48e-090d0e1032cd
STIX ID: report--523ea9d2-367e-5184-a48e-090d0e1032cd
Feed Name: Bleeping Computer
Threat Score
A critical (CVSS 9.8) authentication-bypass vulnerability (CVE-2025-5947) in the Service Finder WordPress theme (versions 6.0 and older) is being actively exploited to gain administrator access via an improperly validated original_user_id cookie and a switch_back=1 request parameter; Wordfence observed over 13,800 exploit attempts (with daily surges >1,500) and identified five high-volume attacker IPs — administrators should update to version 6.1 or remove the theme immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
