Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19966 | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege Escalation. This issue affects Service Finder Booking: from n/a through 6.0. |
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege Escalation. This issue affects Service Finder Booking: from n/a through 6.0. | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.This issue affects Service Finder Booking: from n/a through <= 6.1. |
| Title | WordPress Service Finder Booking <= 6.0 - Privilege Escalation Vulnerability | WordPress Service Finder Booking plugin <= 6.1 - Privilege Escalation Vulnerability |
| References | ||
| Metrics |
cvssV3_1
|
Mon, 07 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Jul 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege Escalation. This issue affects Service Finder Booking: from n/a through 6.0. | |
| Title | WordPress Service Finder Booking <= 6.0 - Privilege Escalation Vulnerability | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-05-12T00:28:53.077Z
Reserved: 2025-01-16T11:33:05.291Z
Link: CVE-2025-23970
Updated: 2025-07-07T14:04:50.493Z
Status : Deferred
Published: 2025-07-04T12:15:25.697
Modified: 2026-04-23T15:24:53.087
Link: CVE-2025-23970
No data.
OpenCVE Enrichment
Updated: 2026-05-02T08:30:26Z
EUVD