Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical2
High0
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-06-04

CVE-2025-4797 - Golo City Travel Guide Wordpress Theme

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for unauthenticated attackers to log in as any user, including administrators, provided they know the user's email address.

THEME Golo City Travel Guide Wordpress Theme

CVE-2025-4797

CRITICAL CVSS 9.8 2025-06-03
Threat Entry Updated 2025-03-13

CVE-2024-12876 - Golo City Travel Guide Wordpress Theme

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

THEME Golo City Travel Guide Wordpress Theme

CVE-2024-12876

CRITICAL CVSS 9.8 2025-03-07
Scroll to top