theme

Houzez Vulnerabilities

32 known security issues reported for the Houzez WordPress theme. Most recent disclosed Nov 26, 2025.

2 critical 4 high 10 medium

Running Houzez on your site? Check whether your installed version is affected.

Scan your site free

Houzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved Search

medium

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is pres...

CVSS:
6.3
Affected:
up to 4.1.6
Fixed in:
4.1.7
Disclosed:
Nov 26, 2025

CVE-2025-9191 on NVD →

Houzez <= 4.1.6 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

medium

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for unauth...

CVSS:
6.1
Affected:
up to 4.1.6
Fixed in:
4.1.7
Disclosed:
Nov 26, 2025

CVE-2025-9163 on NVD →

Houzez [houzez] < 4.2.0

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through < 4.2.0.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Nov 6, 2025

CVE-2025-62053 on NVD →

Houzez [houzez] <= 4.1.1 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Houzez: from n/a through <= 4.1.1.

Affected:
up to 4.1.1
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49952 on NVD →

Houzez < 4.2.0 - Unauthenticated Local File Inclusion

high

The Houzez theme for WordPress is vulnerable to Local File Inclusion in versions up to 4.2.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive dat...

CVSS:
8.1
Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Oct 16, 2025

CVE-2025-62053 on NVD →

Houzez [houzez] < 4.1.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1.

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Aug 28, 2025

CVE-2025-49407 on NVD →

Houzez [houzez] < 4.1.4

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP Local File Inclusion. This issue affects Houzez: from n/a through 4.1.1.

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Aug 28, 2025

CVE-2025-49405 on NVD →

Houzez <= 4.1.1 - Unauthenticated Local File Inclusion

high

The Houzez theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obta...

CVSS:
8.1
Affected:
up to 4.1.1
Fixed in:
4.1.4
Disclosed:
Aug 27, 2025

CVE-2025-49405 on NVD →

Houzez <= 4.1.1 - Reflected Cross-Site Scripting

medium

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 4.1.1
Fixed in:
4.1.4
Disclosed:
Aug 27, 2025

CVE-2025-49407 on NVD →

Houzez <= 4.1.1 - Missing Authorization

medium

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.1.1
Fixed in:
4.1.4
Disclosed:
Aug 20, 2025

CVE-2025-49406 on NVD →

Houzez [houzez] < 4.1.4

unknown

[en] Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1.

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Aug 20, 2025

CVE-2025-49406 on NVD →

Houzez [houzez] < 4.0.8

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP Local File Inclusion. This issue affects Houzez: from n/a through 4.0.4.

Affected:
up to 4.0.8
Fixed in:
4.0.8
Disclosed:
Aug 20, 2025

CVE-2025-53198 on NVD →

Houzez <= 4.0.4 - Missing Authorization

medium

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 4.0.4
Fixed in:
4.1.1
Disclosed:
Jul 16, 2025

CVE-2025-53997 on NVD →

Houzez [houzez] < 4.1.1

unknown

[en] Missing Authorization vulnerability in favethemes Houzez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Houzez: from n/a through 4.0.4.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Jul 16, 2025

CVE-2025-53997 on NVD →

Houzez <= 4.1.1 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The Houzez theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 4.1.1
Fix:
No patched version reported
Disclosed:
Jul 11, 2025

CVE-2025-49952 on NVD →

Houzez <= 4.0.4 - Unauthenticated Local File Inclusion

high

The Houzez theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obta...

CVSS:
8.1
Affected:
up to 4.0.4
Fixed in:
4.0.8
Disclosed:
Jul 1, 2025

CVE-2025-53198 on NVD →

Houzez [houzez] < 3.4.2

unknown

[en] Missing Authorization vulnerability in Houzez.co Houzez. This issue affects Houzez: from n/a through 3.4.0.

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Jan 27, 2025

CVE-2025-24747 on NVD →

Houzez [houzez] < 3.4.2

unknown

[en] Missing Authorization vulnerability in Houzez.co Houzez. This issue affects Houzez: from n/a through 3.4.0.

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Jan 27, 2025

CVE-2025-24754 on NVD →

Houzez <= 3.4.0 - Missing Authorization

medium

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.4.0
Fixed in:
3.4.2
Disclosed:
Jan 24, 2025

CVE-2025-24754 on NVD →

Houzez <= 3.4.1 - Missing Authorization

medium

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Jan 21, 2025

CVE-2025-24747 on NVD →

Houzez <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation

high

The Houzez theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the houzez_ajax_password_reset function not properly verifying a user's identity prior to reseting a password. This makes it possible for authenticated attackers, with subscriber-level access...

CVSS:
8.8
Affected:
up to 3.2.4
Fixed in:
3.3.0
Disclosed:
Sep 17, 2024

CVE-2024-22303 on NVD →

Houzez [houzez] < 3.3.0

unknown

[en] Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Sep 17, 2024

CVE-2024-22303 on NVD →

Houzez [houzez] < 3.2.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS.This issue affects Houzez: from n/a through 3.2.4.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Aug 18, 2024

CVE-2024-43244 on NVD →

Houzez <= 3.2.4 - Reflected Cross-Site Scripting

medium

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Aug 12, 2024

CVE-2024-43244 on NVD →

Houzez [houzez] < 2.7.2

unknown

[en] Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
May 17, 2024

CVE-2023-26540 on NVD →

Houzez [houzez] < 2.8.3

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Dec 20, 2023

CVE-2023-29432 on NVD →

Houzez <= 2.8.2 - Unauthenticated SQL Injection

critical

The Houzez theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into al...

CVSS:
9.8
Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Apr 6, 2023

CVE-2023-29432 on NVD →

Houzez <= 2.7.1 - Privilege Escalation

critical

The Houzez theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.7.1. This is due to improper assignment of privileges on user management/registration that allows users to supply their own role via the houzez_change_user_role and houzez_register_user_with_membership AJAX actions....

CVSS:
9.8
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Feb 27, 2023

CVE-2023-26540 on NVD →

Houzez [houzez] < 1.8.4

unknown

Unauthenticated Cross-Site Scripting (XSS) vulnerability found by m0ze in WordPress Houzez theme (versions <= 1.8.3).

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Jan 28, 2020

Houzez <= 1.8.3 - Reflected Cross-Site Scripting

medium

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' and 'agent_name' parameters in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Jan 11, 2020

Houzez [houzez] < 1.8.4

unknown

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' and 'agent_name' parameters in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Jan 11, 2020

Houzez [houzez] < 1.8.4

unknown

Two Reflected XSS vulnerability were discovered in the &laquo;Houzez - Real Estate WordPress Theme&raquo;, tested version &mdash; v1.8.3.1 Edit (WPScanTeam): January 11th, 2020 - Report received &amp; Envato Contacted January 12th, 2020 - Envato Investigating January 27th, 2020 - v1.8.4 released, fixing the issue...

Affected:
up to 1.8.4
Fixed in:
1.8.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database