CVE-2025-5954
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-5954 is a critical privilege escalation vulnerability in the Service Finder SMS System plugin for WordPress, allowing unauthenticated attackers to register as administrator users via account takeover. It affects all versions of the plugin up to and including 2.0.0. The vulnerability was published on August 1, 2025, and assigned a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is improper privilege management (CWE-269) in the aonesms_fn_savedata_after_signup() function, which handles user registration but fails to restrict or validate the user role submitted during the signup process. An unauthenticated attacker can craft a registration request that specifies the administrator role, and the plugin will accept and assign it without any server-side enforcement. No authentication, special configuration, or user interaction is required to exploit this flaw, making it trivially exploitable over the network (Wordfence, ENISA EUVD).

Impact

Successful exploitation grants an attacker full administrator access to the affected WordPress site, enabling complete compromise of confidentiality, integrity, and availability. An attacker with administrator privileges can install malicious plugins, execute arbitrary code, exfiltrate sensitive data (including user credentials and personal information), deface the site, or use the compromised site as a pivot point for further attacks. The entire WordPress installation and its underlying server infrastructure are at risk (Wordfence).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.074%, reflecting a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the trivial exploitation conditions — no authentication, no user interaction, network-accessible — make it a high-priority target if weaponized (ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Service Finder SMS System plugin (version ≤ 2.0.0) using tools like WPScan, Shodan, or by inspecting plugin directories on publicly accessible WordPress installations.
  2. Craft malicious registration request: Prepare an HTTP POST request targeting the plugin's user registration endpoint that invokes the aonesms_fn_savedata_after_signup() function, including standard registration fields (username, email, password) along with a manipulated role parameter set to administrator.
  3. Submit the request: Send the crafted request to the target site without any prior authentication. The plugin processes the registration without validating or restricting the supplied role value.
  4. Confirm administrator account creation: Log in with the newly registered credentials and verify that the account has WordPress administrator privileges via the dashboard or the /wp-admin/ panel.
  5. Post-exploitation: With administrator access, install a malicious plugin or web shell, exfiltrate data, modify site content, or establish persistent backdoor access (Wordfence, ENISA EUVD).

Indicators of compromise

  • Logs: WordPress authentication logs showing newly created user accounts with the administrator role, especially accounts registered via the plugin's signup function (aonesms_fn_savedata_after_signup); unexpected admin logins from unfamiliar IP addresses shortly after account creation.
  • File System: Presence of unauthorized plugins or web shells installed in the WordPress wp-content/plugins/ directory; modifications to wp-config.php or theme files.
  • WordPress Database: New entries in the wp_users and wp_usermeta tables with wp_capabilities set to administrator for recently created accounts not provisioned by legitimate administrators.
  • Network: Unusual POST requests to the plugin's registration endpoint with role-related parameters; outbound connections from the web server to unknown external hosts following account creation.

Mitigation and workarounds

The primary remediation is to update the Service Finder SMS System plugin to a version beyond 2.0.0 that addresses this vulnerability; site administrators should check the plugin's official page on ThemeForest for an updated release (Wordfence). If an immediate patch is unavailable, consider temporarily disabling user registration on the WordPress site (Settings > General > uncheck "Anyone can register") or deactivating the plugin entirely. Administrators should also audit all recently created user accounts for unauthorized administrator-level entries and remove any suspicious accounts. Implementing a Web Application Firewall (WAF) rule to block unexpected role parameters in registration requests can provide additional defense-in-depth.

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of July 28–August 3, 2025, highlighting it as a critical privilege escalation issue (Wordfence Blog). The vulnerability was also referenced in the CISA vulnerability bulletin for the week of July 28, 2025 (CISA Bulletin). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management