A vulnerability was found in Aonetheme Service Finder Booking Plugin up to 6.2 on WordPress and classified as critical. This issue affects some unknown processing. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-28159. It is possible to launch the attack remotely. No exploit is available.