CVE-2025-2470

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 266

Summary

CVE-2025-2470 is a privilege escalation vulnerability affecting the Service Finder Bookings plugin used in the Service Finder - Directory and Job Board WordPress Theme. Versions up to and including 5.1 are vulnerable. The issue arises due to insufficient user role restrictions in the 'nsl_registration_store_extra_input' function. Unauthenticated attackers can exploit this flaw by registering an account with an arbitrary role, including Administrator, through social login, providing they have the Nextend Social Login plugin installed and configured.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share