CVE-2025-2470 | aonetheme Service Finder Bookings Plugin up to 5.1 on WordPress nsl_registration_store_extra_input privileges assignment
A vulnerability was found in aonetheme Service Finder Bookings Plugin up to 5.1 on WordPress and classified as critical. Affected by this issue is the function nsl_registration_store_extra_input. The manipulation leads to incorrect privilege assignment.
This vulnerability is handled as CVE-2025-2470. The attack may be launched remotely. There is no exploit available.