A vulnerability was found in Aonetheme Service Finder Booking Plugin up to 6.2 on WordPress. It has been classified as critical. Impacted is an unknown function. The manipulation leads to improper privilege management.
This vulnerability is documented as CVE-2026-28161. The attack can be initiated remotely. There is not any exploit available.