Back to overview

CVE-2025-11522

CRITICAL
9.8
CVSS 3.1
Description
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, when Facebook login is enabled. CVE-2025-62064 is likely a duplicate of this CVE.

Metadata

CVE ID
CVE-2025-11522
State
PUBLISHED
Assigner
Wordfence
Reserved
2025-10-08 19:02 UTC
Published
2025-10-09 07:23 UTC
Last updated
2026-04-08 17:27 UTC
Primary CWE
CWE-288
CWE-288 Authentication Bypass Using an Alternate Path or Cha…
Vendor / Product
Elated-Themes / Search & Go - Directory WordPress Theme
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Elated-Themes Search & Go - Directory WordPress Theme 0 ≤ 2.7
Weakness (CWE)
CWESourceDescription
CWE-288 cna CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview