Houzez

Information

Software Type Theme
Software Slug houzez
Software Status Active
Software Author favethemes
Software Website themeforest.net
Software Active Installs 50,363
Software Record Last Updated April 24, 2025

16 Vulnerabilities

6.1
CVE ID Unknown
Jan 11, 2020
Researcher: R3N0
Title Status CVE ID CVSS Researchers Date
Houzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved Search Patched CVE-2025-9191 6.3 Alex Thomas November 26, 2025
Houzez <= 4.1.6 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload Patched CVE-2025-9163 6.1 Alex Thomas November 26, 2025
Houzez < 4.2.0 - Unauthenticated Local File Inclusion Patched CVE-2025-62053 8.1 João Pedro Soares de Alcântara October 16, 2025
Houzez <= 4.1.1 - Reflected Cross-Site Scripting Patched CVE-2025-49407 6.1 Rafie Muhammad August 27, 2025
Houzez <= 4.1.1 - Unauthenticated Local File Inclusion Patched CVE-2025-49405 8.1 Rafie Muhammad August 27, 2025
Houzez <= 4.1.1 - Missing Authorization Patched CVE-2025-49406 5.3 Rafie Muhammad August 20, 2025
Houzez <= 4.0.4 - Missing Authorization Patched CVE-2025-53997 4.3 Tran Nguyen Bao Khanh July 16, 2025
Houzez <= 4.1.1 - Authenticated (Subscriber+) Insecure Direct Object Reference Unpatched CVE-2025-49952 4.3 Tran Nguyen Bao Khanh July 11, 2025
Houzez <= 4.0.4 - Unauthenticated Local File Inclusion Patched CVE-2025-53198 8.1 Tran Nguyen Bao Khanh July 1, 2025
Houzez <= 3.4.0 - Missing Authorization Patched CVE-2025-24754 4.3 Ananda Dhakal January 24, 2025
Houzez <= 3.4.1 - Missing Authorization Patched CVE-2025-24747 5.3 Ananda Dhakal January 21, 2025
Houzez <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation Patched CVE-2024-22303 8.8 luc September 17, 2024
Houzez <= 3.2.4 - Reflected Cross-Site Scripting Patched CVE-2024-43244 6.1 Jorge Rodriguez August 12, 2024
Houzez <= 2.8.2 - Unauthenticated SQL Injection Patched CVE-2023-29432 9.8 Dave Jong April 6, 2023
Houzez <= 2.7.1 - Privilege Escalation Patched CVE-2023-26540 9.8 Dave Jong February 27, 2023
Houzez <= 1.8.3 - Reflected Cross-Site Scripting Patched 6.1 R3N0 January 11, 2020

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation