Cross-site Scripting Vulnerability in Golo Theme by UXPER
CVE-2025-54724

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
28 August 2025

What is CVE-2025-54724?

The Golo theme by UXPER is susceptible to a Cross-site Scripting (XSS) vulnerability that enables attackers to inject malicious scripts into web pages. This vulnerability occurs due to improper sanitization of user inputs during web page generation. Attackers exploiting this flaw can potentially execute arbitrary scripts in users' browsers, leading to unauthorized actions or theft of sensitive information. Users and administrators of the Golo theme are advised to implement appropriate security measures and update to the latest versions to mitigate this threat.

Affected Version(s)

Golo <= 1.7.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.
CVE-2025-54724 : Cross-site Scripting Vulnerability in Golo Theme by UXPER