The WordPress theme Service Finder Bookings has a critical vulnerability CVE-2025-5947 (CVSS 9.8) : due to incorrect validation of a single cookie ( service_finder_switch_back ), an attacker can bypass login and log in as an administrator . The patch was released on 17.7.2025 (version 6.1 ), and automated attacks started immediately — over 13,800 attempts were recorded (a new wave in October 2025).
Are you affected?
- Use a Service Finder theme older than 6.1
- Unknown admin logins or content changes
- New administrator accounts that you didn't create
What to do now
- Update Service Finder to version 6.1 or later.
- Check and delete unknown admin accounts; change all passwords.
- View planted files and scheduled tasks.
Do you suspect that someone has accessed your site? Send us the link — the diagnosis is free, and we will respond within 5 minutes. Urgent repair →
WMD — Super fast support.