A critical authentication bypass vulnerability, tracked as CVE-2025-5947, has been discovered and actively exploited in the Service Finder WordPress theme. This flaw allows unauthenticated attackers to gain access to any account on affected WordPress sites, including those with administrator privileges. The vulnerability stems from improper validation of the original_user_id cookie in the service_finder_switch_back() function, enabling privilege escalation and unauthorized account access. The Service Finder theme, which is widely used for service directory and job board websites, has been sold to over 6,000 customers via Envato Market, making the impact of this vulnerability significant. Security researcher 'Foxyyy' identified the issue and reported it through Wordfence’s bug bounty program on June 8, 2025. The vendor, Aonetheme, released a patch in version 6.1 on July 17, 2025, addressing the vulnerability for all versions prior to and including 6.0. Despite the patch, exploitation attempts began in earnest after public disclosure at the end of July, with Wordfence recording over 13,800 attack attempts since August 1, 2025. Attackers have been observed using specific IP addresses to target the vulnerable account switching function, and a surge of more than 1,500 daily attack attempts was noted for about a week starting September 23. The typical attack involves an HTTP GET request with a switch_back=1 query parameter, allowing the attacker to impersonate any user. Successful exploitation could allow attackers to hijack sites, insert malicious code, redirect users to phishing sites, or use compromised sites to host malware. The full extent of successful compromises remains unclear, but the scale of attempted exploitation highlights the urgency for administrators to update their themes. Administrators are strongly advised to audit their sites for suspicious activity, apply the latest patch, and monitor for unauthorized access. The vulnerability’s critical CVSS score of 9.8 underscores the risk to affected sites. The Service Finder theme’s popularity among active business sites increases the potential for widespread impact. Wordfence continues to monitor exploitation activity and has provided indicators of compromise, including a list of attacking IP addresses. The incident demonstrates the importance of timely patching and vigilant monitoring for WordPress site operators using third-party themes and plugins. Security firms recommend immediate action to mitigate the risk of site takeover and data compromise. The rapid exploitation following public disclosure illustrates the speed at which threat actors can weaponize newly revealed vulnerabilities in popular web platforms.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
By early October 2025, Wordfence said it had blocked more than 13,800 exploitation attempts targeting CVE-2025-5947. The company also published technical details and indicators, including the attack method and a set of source IP addresses tied to the activity.
Starting September 23, 2025, daily intrusion attempts against vulnerable Service Finder sites surpassed 1,500, indicating a notable escalation in exploitation activity. Reports said many attacks originated from five IP addresses and used HTTP GET requests for user impersonation attempts.
Wordfence observed active exploitation of the Service Finder authentication bypass starting on August 1, 2025. Attackers used forged original_user_id cookies and switch_back requests to attempt account takeover on vulnerable WordPress sites.
Wordfence publicly disclosed CVE-2025-5947 on July 31, 2025, describing a critical cookie-validation flaw in the service_finder_switch_back() function that could let unauthenticated attackers log in as any user, including administrators.
The vendor released Service Finder theme version 6.1 on July 17, 2025, fixing a critical authentication bypass flaw in the bundled Bookings plugin that affected versions 6.0 and earlier.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.