Service Finder WordPress theme authentication bypass (CVE-2025-5947, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
Actively exploited CVE-2025-5947 is putting Service Finder WordPress theme sites on version 6.0 and older at risk of administrator takeover. The flaw is an authentication bypass caused by improper validation of the original_user_id cookie in service_finder_switch_back(). Aonetheme fixed the issue in version 6.1, but vulnerable sites can still be logged into without authentication.
Related Happenings
Fortinet FortiWeb WAF authentication bypass actively exploited authentication bypass flaw
Vulnerability
First: 14.11.2025 11:00
Last: 14.11.2025 11:00
Sources 1
About this happening:
**Fortinet FortiWeb WAF** is under **active in-the-wild exploitation** for an **authentication bypass** that can let attackers **take over admin accounts** and **fully compromise...
Fortinet FortiWeb WAF authentication bypass actively exploited authentication bypass flaw
VulnerabilityAbout this happening: **Fortinet FortiWeb WAF** is under **active in-the-wild exploitation** for an **authentication bypass** that can let attackers **take over admin accounts** and **fully compromise...
JobMonster WordPress theme authentication bypass (CVE-2025-5397)
Vulnerability
First: 04.11.2025 09:49
Last: 04.11.2025 09:49
Sources 1
About this happening:
**CVE-2025-5397** in the **JobMonster WordPress theme** is being actively exploited to bypass authentication and hijack **administrator accounts** on sites with **social login** e...
JobMonster WordPress theme authentication bypass (CVE-2025-5397)
VulnerabilityAbout this happening: **CVE-2025-5397** in the **JobMonster WordPress theme** is being actively exploited to bypass authentication and hijack **administrator accounts** on sites with **social login** e...
Service Finder WordPress theme active auth bypass exploitation wave (CVE-2025-5947)
Exploitation Wave
First: 08.10.2025 18:57
Last: 08.10.2025 18:57
Sources 1
How related:
The WordPress security company said it has observed exploitation activity targeting CVE-2025-5947 since August 1, 2025, with over 13,800 attempts detected to date.
About this happening:
**CVE-2025-5947** is being exploited at scale against the **Service Finder WordPress theme**, with attackers using an authentication bypass to log in as administrators and take ov...
Service Finder WordPress theme active auth bypass exploitation wave (CVE-2025-5947)
Exploitation WaveHow related: The WordPress security company said it has observed exploitation activity targeting CVE-2025-5947 since August 1, 2025, with over 13,800 attempts detected to date.
About this happening: **CVE-2025-5947** is being exploited at scale against the **Service Finder WordPress theme**, with attackers using an authentication bypass to log in as administrators and take ov...
Timeline
-
08.10.2025 18:57 1 articles · 7mo ago
Aonetheme ships Service Finder 6.1 fix
Mitigation Patch UpdateAonetheme releases Service Finder version 6.1 to address CVE-2025-5947, closing the improper validation flaw in the original_user_id cookie inside service_finder_switch_back().
Show sources
- Hackers exploit auth bypass in Service Finder WordPress theme — www.bleepingcomputer.com — 08.10.2025 18:57
-
08.10.2025 18:57 2 articles · 7mo ago
Active exploitation begins against Service Finder
Exploitation ObservedThreat actors begin actively exploiting CVE-2025-5947 against Service Finder sites, using requests with switch_back=1 to impersonate existing users and gain administrator access without authentication.
Show sources
- Hackers exploit auth bypass in Service Finder WordPress theme — www.bleepingcomputer.com — 08.10.2025 18:57
- Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme — thehackernews.com — 09.10.2025 09:57
-
08.10.2025 18:57 2 articles · 7mo ago
Service Finder attacks surge in volume
Campaign Scope UpdateWordfence observes a surge of more than 1,500 attack attempts per day beginning September 23, with thousands of requests coming from five IP addresses and more than 13,800 exploit attempts overall.
Show sources
- Hackers exploit auth bypass in Service Finder WordPress theme — www.bleepingcomputer.com — 08.10.2025 18:57
- Hackers exploit auth bypass in Service Finder WordPress theme — www.bleepingcomputer.com — 08.10.2025 18:57
-
08.06.2025 03:00 1 articles · 11mo ago
Foxyyy reports Service Finder auth bypass
Initial DisclosureSecurity researcher Foxyyy reports CVE-2025-5947 through Wordfence's bug bounty program, identifying an authentication bypass in the Service Finder WordPress theme that can let an attacker log in as any user, including an administrator.
Show sources
- Hackers exploit auth bypass in Service Finder WordPress theme — www.bleepingcomputer.com — 08.10.2025 18:57