CVE-2025-4797 describes a critical privilege escalation vulnerability affecting the Golo - City Travel Guide WordPress Theme, impacting all versions up to and including 1.7.0. This flaw allows unauthenticated attackers to log in as any user, including administrators, by knowing only their email address, due to improper identity validation before setting authorization cookies. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a significant risk of full compromise (confidentiality, integrity, availability). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Uxper | Golo - City Travel Guide WordPress Theme | >= 0, <= 1.7.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.