A popular WordPress theme has a worrying security error that can allow full takeover of sites – here is what we know


  • CVE-2025-5947 allows non-approved administrator access in service find WordPress-themed versions ≤ 6.0
  • Over 13,800 exploitation attempts that were observed since August; Attackers are actively targeted at vulnerable places
  • Patching is critical; Blocking five known IPs can help but don’t stop future attacks

Sites that run the popular service find -Bookinger WordPress -theme are actively targeted after the discovery of a critical difficulty vulnerability.

On July 17, Aontheme Version 6.1 released Service Finder, which included a solution for an approval compass failure that affected all versions up to and including 6.0. Since plugin did not validate a user’s cookie value correctly before logging them in, it was possible for non -approved attackers to log in as any user -including admin.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top