CVE-2025-11522
CRITICALSearch & Go - Directory WordPress Theme <2.7 - Auth Bypass
Title source: llmDescription
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, when Facebook login is enabled. CVE-2025-62064 is likely a duplicate of this CVE.
Scores
CVSS v3
9.8
EPSS
0.0033
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-288
Status
published
Products (1)
Elated-Themes/Search & Go - Directory WordPress Theme
< 2.7
Published
Oct 09, 2025
Tracked Since
Feb 18, 2026