Privilege Escalation Vulnerability in Golo City Travel Guide Theme for WordPress
CVE-2025-4797
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 June 2025
What is CVE-2025-4797?
The Golo - City Travel Guide WordPress Theme is susceptible to a privilege escalation vulnerability that allows unauthorized users to exploit the system. This security flaw arises from the plugin's failure to adequately verify a user's identity before setting an authorization cookie. Consequently, attackers can potentially gain access to user accounts, including those of administrators, simply by knowing the target user's email address. This vulnerability poses significant risks to the integrity and security of the websites utilizing this theme.
Affected Version(s)
Golo - City Travel Guide WordPress Theme * <= 1.7.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Friderika Baranyai