Service Finder Bookings WordPress plugin <= 6.0 contains a privilege escalation caused by improper validation of user cookie in service_finder_switch_back() function, letting unauthenticated attackers login as any user including admins.
id: CVE-2025-5947
info:
name: Service Finder Bookings - Authentication Bypass
author: sedat4ras
...