PT-2025-41360 · WordPress · Search & Go - Directory Wordpress Theme

Khanhhnahk1

·

Published

2025-10-09

·

Updated

2025-10-09

·

CVE-2025-11522

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Search & Go - Directory WordPress Theme versions prior to 2.7
Description The Search & Go - Directory WordPress Theme is susceptible to authentication bypass, potentially leading to account takeover. This occurs due to inadequate user validation within the search and go elated check facebook user() function. When Facebook login is enabled, unauthenticated attackers may gain access to other user accounts, including administrator accounts.
Recommendations Update to a version newer than 2.7.

Fix

LPE

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-11522

Affected Products

Search & Go - Directory Wordpress Theme