CVE Alert: CVE-2025-5955 – aonetheme – Service Finder SMS System
CVE-2025-5955
The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user’s phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.
AI Summary Analysis
Risk verdict
Why this matters
Most likely attack path
Who is most exposed
Detection ideas
- Unauthorised admin logins from new devices or IPs without password prompts.
- Rapid creation or elevation of user accounts to admin or other high-privilege roles.
- Access to wp-admin or REST endpoints by unusual geolocations or during odd hours.
- Sudden spikes in login activity targeting the admin area; anomalous session tokens.
Mitigation and prioritisation
- Patch to the latest plugin version or remove/disable the plugin if no fix is available.
- Enforce strict admin access controls: MFA for admin accounts, IP allowlists, and disable public admin access where feasible.
- Implement web application firewall rules to block unauthenticated login abuse and monitor for abnormal login patterns.
- Conduct change management: test patch in staging, back up sites, and schedule a deployment window.
- Strengthen monitoring: enable detailed authentication logging and alert on admin login anomalies.
- If KEV is present or EPSS ≥ 0.5, treat as priority 1. If not known, default to high-priority remediation based on CVSS signals.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.