CVE-2025-62064

9.8

Elated-Themes · Search & Go

The Elated-Themes Search & Go WordPress theme (up to version 2.7) contains an authentication bypass vulnerability in the password recovery mechanism, allowing unauthorized access.

Executive summary

An authentication bypass vulnerability in the Search & Go WordPress theme allows attackers to compromise user accounts, requiring an immediate update to the latest available version.

Vulnerability

This vulnerability involves an authentication bypass via an alternate path or channel within the theme's password recovery process. Per the CVSS vector (PR:N), the vulnerability is exploitable by unauthenticated attackers.

Business impact

An authentication bypass allows attackers to hijack user accounts, including administrative accounts, potentially leading to unauthorized data access, site defacement, or complete site takeover. The 9.8 CVSS score highlights the extreme risk to the confidentiality, integrity, and availability of the affected WordPress installation.

Remediation

Immediate Action: Update the Search & Go theme to the latest patched version provided by Elated-Themes.

Proactive Monitoring: Monitor user account activity logs for anomalous password reset requests or unauthorized access from unrecognized IP addresses.

Compensating Controls: Disable the theme's password recovery functionality if an update is not immediately feasible, or implement strict rate-limiting on the password reset endpoint via a WAF.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the ability for unauthenticated attackers to bypass security controls, this vulnerability is of the highest priority. Administrators should apply the theme update immediately and perform a security audit of user accounts to ensure no unauthorized access has already occurred.

More Elated-Themes CVEs