PHP Object Injection Vulnerability in Houzez Theme by Favethemes
CVE-2025-9191
6.3MEDIUM
What is CVE-2025-9191?
The Houzez theme, developed by Favethemes, is susceptible to PHP Object Injection due to improper deserialization of untrusted inputs in saved-search-item.php. This vulnerability impacts all versions up to and including 4.1.6, allowing authenticated users with Subscriber-level access or higher to inject PHP Objects. Although the vulnerability lacks a known PHP Object Pollution (POP) chain in the original theme, its risk potentially escalates if other plugins or themes with a POP chain are installed. Such conditions could enable attackers to carry out actions like deleting files, accessing sensitive information, or executing arbitrary code, depending on the available POP chain.
Affected Version(s)
Houzez * <= 4.1.6