Vulnerability Description
The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://themeforest.net/item/service-finder-service-and-business-listing-wordpre
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a1f62cda-262b-46d9-a83
FAQ
What is CVE-2025-2470?
CVE-2025-2470 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1....
How severe is CVE-2025-2470?
CVE-2025-2470 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-2470?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.