CERT-In Vulnerability Note
CIVN-2023-0070
Privilege Escalation Vulnerability in WordPress Houzez theme
Original Issue Date:March 10, 2023
Severity Rating: CRITICAL
Software Affected
The following versions of the Houzez plugin are affected:- Versions 2.7.1 and earlier
- Versions 2.6.3 and earlier
Overview
A vulnerability has been reported in WordPress Houzez theme which could allow a remote attacker to gain elevated privileges on the system.
Description
The vulnerability exists in WordPress Houzez theme plugin and Houzez Login Register plugin due to privilege escalation. An attacker could exploit this vulnerability by sending a specially crafted request.
Successful exploitation of this vulnerability could allow a remote attacker to gain elevated privileges on the system.
Note: It has been reported that the vulnerabilities are being exploited in wild.
Solution
Update the WordPress Houzez theme to the latest available version.
References
https://patchstack.com/database/vulnerability/houzez/wordpress-houzez-theme-2-7-1-privilege-escalation
https://patchstack.com/database/vulnerability/houzez-login-register/wordpress-houzez-login-register-plugin-2-6-3-privilege-escalation
https://patchstack.com/articles/psa-houzez-theme-unauthenticated-privilege-escalation-vulnerability-exploited-in-the-wild/
CVE Name
CVE-2023-26540
CVE-2023-26009
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|