Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Houzez — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Houzez, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations (CWE) associated with the Houzez product developed by Houzez LLC. The content aggregates known security vulnerabilities, configuration issues, and coding flaws that have been identified within this WordPress real estate theme and its related plugins. The data covers publicly disclosed weaknesses from early 2021 through the present, reflecting a comprehensive view of the product's security posture over time. By consolidating these records, the page allows security professionals and site administrators to track specific vendor advisories and monitor the evolution of reported issues. Users can gain a deeper understanding of prevalent weakness classes, such as Cross-Site Scripting (XSS) or SQL Injection, as they specifically manifest within the Houzez ecosystem. Furthermore, the resource enables a thorough lookup of the product’s vulnerability history, helping teams assess risk exposure based on past incidents and remediation efforts. This historical context is essential for prioritizing security audits and ensuring that deployed instances are patched against known defects. The aggregation serves as a neutral reference point for evaluating the overall security hygiene of the software, independent of marketing narratives or promotional statements. It provides factual data necessary for informed decision-making regarding updates, code reviews, and infrastructure hardening strategies for any organization utilizing this specific digital asset.

Vendor: Favethemes

CVE ID Title CVSS Severity Published
CVE-2025-9163 Houzez <= 4.1.6 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload CWE-79 6.1 Medium 2025-11-26
CVE-2025-9191 Houzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved Search CWE-502 6.3 Medium 2025-11-26
CVE-2025-62053 WordPress Houzez theme < 4.2.0 - Local File Inclusion vulnerability CWE-98 8.1 High 2025-11-06
CVE-2025-49952 WordPress Houzez theme <= 4.2.5 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2025-10-22
CVE-2025-49405 WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerability CWE-98 4.3 Medium 2025-08-28
CVE-2025-49407 WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerability CWE-79 8.8 High 2025-08-28
CVE-2025-49406 WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerability CWE-862 8.5 High 2025-08-20
CVE-2025-53198 WordPress Houzez theme <= 4.0.4 - Local File Inclusion Vulnerability CWE-98 8.1 High 2025-08-20
CVE-2025-53997 WordPress Houzez theme <= 4.0.4 - Broken Access Control Vulnerability CWE-862 4.3 Medium 2025-07-16
CVE-2025-24747 WordPress Houzez theme <= 3.4.0 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-01-27
CVE-2025-24754 WordPress Houzez theme <= 3.4.0 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-01-27
CVE-2024-22303 WordPress Houzez theme <= 3.2.4 - Privilege Escalation vulnerability CWE-266 8.8 High 2024-09-17
CVE-2024-43244 WordPress houzez Theme By FaveThemes <= 3.2.4 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-08-18
CVE-2023-26540 WordPress Houzez theme <= 2.7.1 - Privilege Escalation CWE-269 9.8 Critical 2024-05-17

All 14 known CVE vulnerabilities affecting Houzez with full Chinese analysis, references, and POCs where available.