Authorization Bypass in Houzez by Favethemes
CVE-2025-49952

6.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 October 2025

What is CVE-2025-49952?

The Houzez theme by Favethemes contains a vulnerability that allows unauthorized users to bypass secure access controls due to improperly configured security levels. This risk is particularly prevalent in versions up to 4.1.1, where exploitation can lead to unauthorized access to sensitive resources. Proper security measures and updates should be implemented to mitigate this risk.

Affected Version(s)

Houzez <= n/a

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.