theme

Golo Vulnerabilities

20 known security issues reported for the Golo WordPress theme. Most recent disclosed Mar 25, 2026.

4 critical 2 high 3 medium

Running Golo on your site? Check whether your installed version is affected.

Scan your site free

Golo [golo] <= 1.7.0 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.

Affected:
up to 1.7.0
Fix:
No patched version reported
Disclosed:
Mar 25, 2026

CVE-2026-27051 on NVD →

Golo [golo] < 1.7.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5.

Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Mar 25, 2026

CVE-2026-23973 on NVD →

Golo - City Travel Guide WordPress Theme < 1.7.5 - Reflected Cross-Site Scripting

medium

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

CVSS:
6.1
Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Mar 23, 2026

CVE-2026-23973 on NVD →

Golo - Privilege Escalation vulnerability

critical

Privilege Escalation vulnerability

CVSS:
9.8
Affected:
up to 1.7.0
Fix:
No patched version reported
Disclosed:
Mar 12, 2026

Golo - City Travel Guide WordPress Theme <= 1.7.0 - Unauthenticated Privilege Escalation

critical

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS:
9.8
Affected:
up to 1.7.0
Fix:
No patched version reported
Disclosed:
Mar 12, 2026

CVE-2026-27051 on NVD →

Golo < 1.7.5 - Authenticated (Contributor+) Local File Inclusion

high

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to 1.7.5 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any...

CVSS:
7.5
Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Feb 5, 2026

CVE-2026-23975 on NVD →

Golo < 1.7.5 - Missing Authorization

medium

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.7.5 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Feb 5, 2026

CVE-2026-23974 on NVD →

Golo [golo] < 1.7.5

unknown

[en] Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo: from n/a through < 1.7.5.

Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Jan 22, 2026

CVE-2026-23974 on NVD →

Golo [golo] < 1.7.5

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5.

Affected:
up to 1.7.5
Fixed in:
1.7.5
Disclosed:
Jan 22, 2026

CVE-2026-23975 on NVD →

Golo [golo] < 1.7.1

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo allows Authentication Abuse. This issue affects Golo: from n/a through 1.7.0.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Aug 28, 2025

CVE-2025-54725 on NVD →

Golo [golo] < 1.7.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo allows Reflected XSS. This issue affects Golo: from n/a through 1.7.1.

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Aug 28, 2025

CVE-2025-54724 on NVD →

Golo <= 1.7.1 - Reflected Cross-Site Scripting

medium

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Aug 26, 2025

CVE-2025-54724 on NVD →

Golo <= 1.7.0 - Authentication Bypass to Account Takeover

critical

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for unauthenticate...

CVSS:
9.8
Affected:
up to 1.7.0
Fixed in:
1.7.1
Disclosed:
Jun 2, 2025

CVE-2025-4797 on NVD →

Golo [golo] < 1.6.11

unknown

[en] The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated...

Affected:
up to 1.6.11
Fixed in:
1.6.11
Disclosed:
Mar 7, 2025

CVE-2024-12876 on NVD →

Golo - Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change

critical

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attac...

CVSS:
9.8
Affected:
up to 1.6.10
Fixed in:
1.6.11
Disclosed:
Mar 6, 2025

CVE-2024-12876 on NVD →

Golo [golo] < 1.3.3

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Vlad Vector in WordPress Golo premium theme (versions <= 1.3.2).

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jul 15, 2020

Golo - City Travel Guide WordPress Theme < 1.3.3 - Reflected Cross-Site Scripting

high

The "Golo - City Travel Guide WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions before 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
7.1
Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jul 11, 2020

Golo [golo] < 1.3.3

unknown

The "Golo - City Travel Guide WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions before 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jul 11, 2020

Golo [golo] < 1.3.3

unknown

An Unauthenticated Reflected XSS vulnerability was discovered in the Golo theme v1.3.2 for WordPress.

Affected:
up to 1.3.3
Fixed in:
1.3.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database