CVE-2025-54725

WordPress Golo Theme <= 1.7.0 - Broken Authentication Vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo allows Authentication Abuse. This issue affects Golo: from n/a through 1.7.0.


We have discovered 70 live websites that are affected by CVE-2025-54725.

Run a Free Instant Scan




Affected Software

Product  Golo
Category Wordpress Themes
Vulnerable Domains70 live websites (100% of Golo install base)
Vulnerable Versions
  • from 0 through 1.7
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Aug 28, 2025
  • Updated - Aug 28, 2025

Credits

  • Aiden (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-54725
United States11 websites



Italy10 websites
GB8 websites
Greece6 websites
Germany4 websites
Turkey4 websites
Brazil3 websites
France3 websites
India2 websites
Japan2 websites

Website Distribution by TLD

Number of websites using CVE-2025-54725
.com24 websites
.it8 websites
.com.br4 websites
.org3 websites
.co2 websites
.ru2 websites
.net2 websites
.ch1 websites
.co.uk1 websites
.de1 websites

Websites affected by CVE-2025-54725

Top websites that are affected by CVE-2025-54725. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.travel United States*,***,***
**********.ch Switzerland*,***,***
*******.net GB*,***,***
**********.com Turkey*,***,***
*************.com United States*,***,***
****************.it Italy*,***,***
********.in India*,***,***
*******.az Azerbaijan*,***,***
***********.***.ng Nigeria*,***,***
****************.it Italy*,***,***
See full domain list

FAQ

CVE-2025-54725 is Authentication Bypass Using an Alternate Path or Channel in Golo
A total of 70 websites have been identified as vulnerable to CVE-2025-54725, based on global website indexing conducted by WebTechSurvey.
The Golo is affected by the CVE-2025-54725 vulnerability.
Golo versions up to and including 1.7 are vulnerable to CVE-2025-54725.