| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-6574 | Service Finder Bookings < 6.1 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover | aonetheme | Service Finder Bookings | High | 8.8 | 2025-11-01 06:40:36 | Deep Dive |
| CVE-2025-5949 | Service Finder Bookings <= 6.0 - Authenticated (Subscriber+) Privilege Escalation via change_candidate_password | aonetheme | Service Finder Bookings | High | 8.8 | 2025-11-01 04:27:42 | Deep Dive |
| CVE-2025-5948 | Service Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_business | aonetheme | Service Finder Bookings | Critical | 9.8 | 2025-09-19 05:28:51 | Deep Dive |
| CVE-2025-5955 | Service Finder SMS System <= 2.0.0 - Authentication Bypass | aonetheme | Service Finder SMS System | High | 8.1 | 2025-09-19 04:27:05 | Deep Dive |
| CVE-2025-5947 | Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie | aonetheme | Service Finder Bookings | Critical | 9.8 | 2025-08-01 03:24:46 | Deep Dive |
| CVE-2025-5954 | Service Finder SMS System <= 2.0.0 - Unauthenticated Privilege Escalation | aonetheme | Service Finder SMS System | Critical | 9.8 | 2025-08-01 02:24:18 | Deep Dive |
| CVE-2025-23970 | WordPress Service Finder Booking plugin <= 6.1 - Privilege Escalation Vulnerability | aonetheme | Service Finder Booking | Critical | 9.8 | 2025-07-04 11:18:12 | Deep Dive |
| CVE-2025-2470 | Service Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input' | aonetheme | Service Finder Bookings | Critical | 9.8 | 2025-04-25 11:12:53 | Deep Dive |
| CVE-2024-13442 | Service Finder Bookings <= 5.0 - Unauthenticated Privilege Escalation via Account Takeover | aonetheme | Service Finder Bookings | Critical | 9.8 | 2025-03-19 11:10:38 | Deep Dive |