SQL Injection Vulnerability in Homey Theme by Favethemes
CVE-2025-52834

9.3CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
27 June 2025

What is CVE-2025-52834?

The Homey theme by Favethemes contains a vulnerability that allows for SQL Injection, which could enable attackers to manipulate SQL queries through improperly sanitized input. This issue impacts all versions from n/a to 2.4.5, potentially allowing unauthorized access to the database and exposure of sensitive information.

Affected Version(s)

Homey <= 2.4.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ann (Patchstack Alliance)
.