Privilege Escalation Vulnerability in Golo City Travel Guide Theme for WordPress
CVE-2025-4797
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 June 2025
What is CVE-2025-4797?
The Golo - City Travel Guide WordPress Theme is susceptible to a privilege escalation vulnerability that allows unauthorized users to exploit the system. This security flaw arises from the plugin's failure to adequately verify a user's identity before setting an authorization cookie. Consequently, attackers can potentially gain access to user accounts, including those of administrators, simply by knowing the target user's email address. This vulnerability poses significant risks to the integrity and security of the websites utilizing this theme.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Golo - City Travel Guide WordPress Theme * <= 1.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved