CVE-2025-6574 | aonetheme Service Finder Bookings Plugin up to 6.0 on WordPress authorization (EUVD-2025-37430)
A vulnerability classified as critical was found in aonetheme Service Finder Bookings Plugin up to 6.0 on WordPress. The impacted element is an unknown function of the component Service. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2025-6574. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.