Thème WordPress

Vulnérabilités Houzez

Cette page rassemble les failles publiées pour Houzez, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
2Critiques
15Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Houzez

16 fiches

CVE-2025-9163 Moyenne · 6,1
Houzez

Houzez <= 4.1.6 – Unauthenticated Stored Cross-Site Scripting via SVG File Upload

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This…

Versions affectées

*-4.1.6

Correctif

4.1.7

Publication

26/11/2025

CVE-2025-49407 Moyenne · 6,1
Houzez

Houzez <= 4.1.1 – Reflected Cross-Site Scripting

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-4.1.1

Correctif

4.1.4

Publication

27/08/2025

CVE-2025-49406 Moyenne · 5,3
Houzez

Houzez <= 4.1.1 – Missing Authorization

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.1. This makes it possible for unauthenticated attackers to perform an unauthorized…

Versions affectées

*-4.1.1

Correctif

4.1.4

Publication

20/08/2025

CVE-2025-53997 Moyenne · 4,3
Houzez

Houzez <= 4.0.4 – Missing Authorization

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and…

Versions affectées

*-4.0.4

Correctif

4.1.1

Publication

16/07/2025

CVE-2025-24754 Moyenne · 4,3
Houzez

Houzez <= 3.4.0 – Missing Authorization

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and…

Versions affectées

*-3.4.0

Correctif

3.4.2

Publication

24/01/2025

CVE-2025-24747 Moyenne · 5,3
Houzez

Houzez <= 3.4.1 – Missing Authorization

The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and…

Versions affectées

*-3.4.1

Correctif

3.4.2

Publication

21/01/2025

CVE-2024-43244 Moyenne · 6,1
Houzez

Houzez <= 3.2.4 – Reflected Cross-Site Scripting

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-3.2.4

Correctif

3.2.5

Publication

12/08/2024

CVE-2023-29432 Critique · 9,8
Houzez

Houzez <= 2.8.2 – Unauthenticated SQL Injection

The Houzez theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

[*, 2.8.3)

Correctif

2.8.3

Publication

06/04/2023

CVE-2023-26540 Critique · 9,8
Houzez

Houzez <= 2.7.1 – Privilege Escalation

The Houzez theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.7.1. This is due to improper assignment of privileges on user management/registration that allows users to supply their own role via the…

Versions affectées

*-2.7.1

Correctif

2.7.2

Publication

27/02/2023

Vulnérabilité Moyenne · 6,1
Houzez

Houzez <= 1.8.3 – Reflected Cross-Site Scripting

The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' and 'agent_name' parameters in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

11/01/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités