The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for unauthenticated attackers to log in as any user, including administrators, provided they know the user's email address.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 03 Jun 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for unauthenticated attackers to log in as any user, including administrators, provided they know the user's email address. | |
Title | Golo <= 1.7.0 - Authentication Bypass to Account Takeover | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-06-03T04:22:16.085Z
Updated: 2025-06-03T14:50:25.735Z
Reserved: 2025-05-15T18:22:15.692Z
Link: CVE-2025-4797

Updated: 2025-06-03T14:50:22.915Z

Status : Awaiting Analysis
Published: 2025-06-03T05:15:20.323
Modified: 2025-06-04T14:54:33.783
Link: CVE-2025-4797

No data.