External risk intelligence

Search & Go Directory WordPress Theme Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-11522

The vulnerability exists in a WordPress theme component that handles external authentication (Facebook login). WordPress sites and their themes are commonly deployed as public-facing web applications. Because this functionality is intended for user interaction on a public website, the vulnerable code path is inherently exposed to the internet in common deployment patterns.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the Search & Go - Directory WordPress Theme, potentially allowing unauthenticated attackers to take over user accounts, including administrator accounts, if Facebook login is enabled. This issue stems from insufficient user validation within a specific function of the theme.

  • Unauthenticated users can hijack accounts.
  • This could compromise administrative access.
  • Confirm relevance to protect user data.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication to take over any user account, including administrators, if the website uses the Search & Go - Directory WordPress Theme and has enabled Facebook login. This is possible because the theme does not properly validate users when checking Facebook authentication.

  • Entry condition: Facebook login enabled.
  • Trigger point: Insufficient user validation function.
  • Resulting risk: Gain access to any user account.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to bypass login and take over any user account, including administrator accounts, on WordPress sites using the Search & Go - Directory theme when Facebook login is enabled. This could expose sensitive system data and user information.

  • User accounts, including administrators.
  • Via unauthorized login when Facebook is enabled.
  • Complete account takeover and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

WordPress site owners and administrators are responsible for managing their themes and user authentication. The initial focus should be on identifying all WordPress instances utilizing the affected theme, confirming if the Facebook login feature is enabled, and assessing business criticality and user impact. Once identified, engage the accountable application owner to plan remediation, which may involve coordinating with the theme vendor or implementing temporary risk-reduction measures.

  • Application owners should address this.
  • Verify Facebook login is enabled.
  • Plan vendor coordination for updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Search & Go - Directory WordPress Theme?

It is a specialized WordPress theme designed for building directory websites. It provides the layout, styling, and functionality required for listing services or locations. This theme includes built-in features for user management and account authentication, such as integration with Facebook login, which allows users to register or access the site using their existing social media credentials.

What does Authentication Bypass mean for CVE-2025-11522?

This vulnerability is classified as CWE-288, which involves improper authentication. In this specific case, the theme fails to correctly verify the identity of a user when the Facebook login process is triggered. Because the validation logic is flawed, the system can be tricked into accepting an unauthenticated user as a legitimate, logged-in user, potentially granting them full control over any account, including administrative profiles.

How does an attacker trigger this vulnerability?

The flaw exists within the search_and_go_elated_check_facebook_user() function. It is only reachable if the website owner has enabled the Facebook login feature within the theme settings. If Facebook login is disabled or not used on the site, this specific code path remains inactive, and the authentication bypass cannot be leveraged to gain unauthorized access.

Is my website relevant to this threat?

According to Halo Surface Signal, this vulnerability is likely relevant because WordPress themes are typically deployed as public-facing web applications. Since the Facebook login feature is designed for visitor interaction, the vulnerable function is inherently exposed to the internet. If you use this theme and have enabled Facebook login, your site is directly accessible to potential attackers.

What steps should I take if I use this theme?

Start by auditing your WordPress instances to confirm if this specific theme is active. Check your theme settings to determine if Facebook login is enabled. If you are running an affected version, prioritize identifying the business impact of a potential account takeover. Coordinate with your team to plan for vendor updates or consider disabling Facebook login as a temporary measure to reduce risk.

References