
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-5954 is a critical privilege escalation vulnerability in the Service Finder SMS System plugin for WordPress, allowing unauthenticated attackers to register as administrator users via account takeover. It affects all versions of the plugin up to and including 2.0.0. The vulnerability was published on August 1, 2025, and assigned a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is improper privilege management (CWE-269) in the aonesms_fn_savedata_after_signup() function, which handles user registration but fails to restrict or validate the user role submitted during the signup process. An unauthenticated attacker can craft a registration request that specifies the administrator role, and the plugin will accept and assign it without any server-side enforcement. No authentication, special configuration, or user interaction is required to exploit this flaw, making it trivially exploitable over the network (Wordfence, ENISA EUVD).
Successful exploitation grants an attacker full administrator access to the affected WordPress site, enabling complete compromise of confidentiality, integrity, and availability. An attacker with administrator privileges can install malicious plugins, execute arbitrary code, exfiltrate sensitive data (including user credentials and personal information), deface the site, or use the compromised site as a pivot point for further attacks. The entire WordPress installation and its underlying server infrastructure are at risk (Wordfence).
aonesms_fn_savedata_after_signup() function, including standard registration fields (username, email, password) along with a manipulated role parameter set to administrator./wp-admin/ panel.administrator role, especially accounts registered via the plugin's signup function (aonesms_fn_savedata_after_signup); unexpected admin logins from unfamiliar IP addresses shortly after account creation.wp-content/plugins/ directory; modifications to wp-config.php or theme files.wp_users and wp_usermeta tables with wp_capabilities set to administrator for recently created accounts not provisioned by legitimate administrators.The primary remediation is to update the Service Finder SMS System plugin to a version beyond 2.0.0 that addresses this vulnerability; site administrators should check the plugin's official page on ThemeForest for an updated release (Wordfence). If an immediate patch is unavailable, consider temporarily disabling user registration on the WordPress site (Settings > General > uncheck "Anyone can register") or deactivating the plugin entirely. Administrators should also audit all recently created user accounts for unauthorized administrator-level entries and remove any suspicious accounts. Implementing a Web Application Firewall (WAF) rule to block unexpected role parameters in registration requests can provide additional defense-in-depth.
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of July 28–August 3, 2025, highlighting it as a critical privilege escalation issue (Wordfence Blog). The vulnerability was also referenced in the CISA vulnerability bulletin for the week of July 28, 2025 (CISA Bulletin). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."