Service Finder Bookings - Authentication Bypass
Service Finder Bookings WordPress plugin <= 6.0 contains a privilege escalation caused by improper validation of user cookie in service_finder_switch_back() function, letting unauthenticated attackers login as any user including admins.
sf-bookingPoC 已收录
CVSS—