Privilege Escalation Vulnerability in Golo City Travel Guide Theme for WordPress
CVE-2025-4797

9.8CRITICAL

What is CVE-2025-4797?

The Golo - City Travel Guide WordPress Theme is susceptible to a privilege escalation vulnerability that allows unauthorized users to exploit the system. This security flaw arises from the plugin's failure to adequately verify a user's identity before setting an authorization cookie. Consequently, attackers can potentially gain access to user accounts, including those of administrators, simply by knowing the target user's email address. This vulnerability poses significant risks to the integrity and security of the websites utilizing this theme.

Affected Version(s)

Golo - City Travel Guide WordPress Theme * <= 1.7.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Friderika Baranyai
.
CVE-2025-4797 : Privilege Escalation Vulnerability in Golo City Travel Guide Theme for WordPress