Critical 9.8 Unfixed
2026-03-25≤ 1.7.0
CVE-2026-27051
Minimum safe version
1.7.5
Update to 1.7.5 or later to address 10 fixable vulnerabilities
CVE-2026-27051
CVE-2026-23973
Golo < 1.7.5 - Authenticated (Contributor+) Local File Inclusion
Golo < 1.7.5 - Missing Authorization
CVE-2025-54724
CVE-2025-54725
Golo <= 1.7.0 - Authentication Bypass to Account Takeover
CVE-2024-12876
Golo < 1.3.3 - Unauthenticated Reflected XSS
Golo - City Travel Guide WordPress Theme < 1.3.3 - Reflected Cross-Site Scripting
WordPress Golo premium theme <= 1.3.2 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability