
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
The Golo - City Travel Guide WordPress Theme (version <= 1.6.10) contains a critical vulnerability (CVE-2024-12876) that allows unauthorized users to change arbitrary user passwords. The vulnerability was publicly disclosed on March 6, 2025, and received a CVSS score of 9.8 (Critical) (Wordfence).
The vulnerability stems from improper authorization controls in the password change functionality. The theme does not properly validate a user's identity before allowing password updates, enabling unauthenticated attackers to modify any user's password (Wordfence).
This vulnerability could allow attackers to take control of any user account on affected WordPress sites, including administrator accounts. This could lead to complete site compromise, data theft, and unauthorized content modifications (Wordfence).
Users should immediately update to version 1.6.12 or later of the Golo theme, which contains a fix for this vulnerability. The update was released on February 19, 2025, and addresses the password change form error (ThemeForest).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”