PHP Object Injection Vulnerability in Houzez Theme by Favethemes
CVE-2025-9191

6.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
26 November 2025

What is CVE-2025-9191?

The Houzez theme, developed by Favethemes, is susceptible to PHP Object Injection due to improper deserialization of untrusted inputs in saved-search-item.php. This vulnerability impacts all versions up to and including 4.1.6, allowing authenticated users with Subscriber-level access or higher to inject PHP Objects. Although the vulnerability lacks a known PHP Object Pollution (POP) chain in the original theme, its risk potentially escalates if other plugins or themes with a POP chain are installed. Such conditions could enable attackers to carry out actions like deleting files, accessing sensitive information, or executing arbitrary code, depending on the available POP chain.

Affected Version(s)

Houzez * <= 4.1.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Thomas
.