Authorization Bypass in Houzez by Favethemes
CVE-2025-49952
6.3MEDIUM
What is CVE-2025-49952?
The Houzez theme by Favethemes contains a vulnerability that allows unauthorized users to bypass secure access controls due to improperly configured security levels. This risk is particularly prevalent in versions up to 4.1.1, where exploitation can lead to unauthorized access to sensitive resources. Proper security measures and updates should be implemented to mitigate this risk.
Affected Version(s)
Houzez <= n/a
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)