---
id: CVE-2025-11522
title: >-
  The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable
  to Authentication Bypass via account takeover in all versions up to, and
  including, 2.7
summary: >-
  The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable
  to Authentication Bypass via account takeover in all versions up to, and
  including, 2.7. This is due to insufficient user validation in the
  search_and_go_elate…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-288
published: '2025-10-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11522'
references:
  - url: >-
      https://themeforest.net/item/search-go-modern-smart-directory-theme/15365040
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/da590a65-8728-4577-b6e4-ecebc2a2277d?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00555
epssPercentile: 0.44549
ingestedAt: '2026-10-08T13:42:55.036Z'
---

## Overview

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, when Facebook login is enabled. CVE-2025-62064 is likely a duplicate of this CVE.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
