Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2470

Опубликовано: 25 апр. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.

EPSS

Процентиль: 50%
0.00266
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 9.8
github
10 месяцев назад

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.

EPSS

Процентиль: 50%
0.00266
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-266