Houzez Login Register <= 3.3.3 - Unauthenticated Privilege Escalation
critical
The Houzez Login Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of administrator.
- CVSS:
- 9.8
- Affected:
- up to 3.3.3
- Fix:
- No patched version reported
- Disclosed:
- Jul 8, 2026
CVE-2026-57768 on NVD →
Houzez Login Register <= 3.2.5 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
high
The Houzez Login Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.5. This is due to the houzez_agency_agent_update function not properly verifying a user's identity prior to allowing them to update user details like email address. This makes it possible for a...
- CVSS:
- 8.8
- Affected:
- up to 3.2.5
- Fixed in:
- 3.3.0
- Disclosed:
- Sep 17, 2024
CVE-2024-21743 on NVD →
Houzez Login Register [houzez-login-register] < 3.3.0
unknown
[en] Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Sep 17, 2024
CVE-2024-21743 on NVD →
Houzez Login Register [houzez-login-register] < 2.6.4
unknown
[en] Improper Privilege Management vulnerability in favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.4
- Disclosed:
- May 17, 2024
CVE-2023-26009 on NVD →
Houzez Login Register <= 2.6.3 - Privilege Escalation
critical
The Houzez Login Register plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.3. This is due to improper assignment of privileges on user registration that allows users to supply their own role via the houzez_register AJAX action. This makes it possible for unauthenticated a...
- CVSS:
- 9.8
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Feb 23, 2023
CVE-2023-26009 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database