PT-2025-23567 · WordPress · The Golo - City Travel Guide Wordpress Theme
Friderika Baranyai
·
Published
2025-06-03
·
Updated
2025-06-08
·
CVE-2025-4797
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Golo - City Travel Guide WordPress Theme version 1.7.0 and earlier
Description
The issue is related to privilege escalation via account takeover due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This allows unauthenticated attackers to log in as any user, including administrators, if they know the user's email address.
Recommendations
For versions up to and including 1.7.0, update to a version that fixes the authentication bypass issue.
As a temporary workaround, consider restricting access to sensitive areas of the WordPress site to minimize the risk of exploitation.
Avoid using email addresses as the sole means of identification for user accounts until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Golo - City Travel Guide Wordpress Theme