Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Houzez theme to the latest available version (at least 4.1.4).
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26008 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Favethemes Houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a before 4.1.4. |
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-35 | |
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path Traversal: '.../...//' vulnerability in Favethemes Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through <= 2.0. | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Favethemes Houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a before 4.1.4. |
| Title | WordPress Pro Bulk Watermark Plugin for WordPress Theme <= 2.0 - Path Traversal Vulnerability | WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerability |
| Weaknesses | CWE-98 | |
| References |
|
Thu, 23 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-98 | |
| References |
|
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Favethemes Houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a before 4.1.4. | Path Traversal: '.../...//' vulnerability in Favethemes Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through <= 2.0. |
| Title | WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerability | WordPress Pro Bulk Watermark Plugin for WordPress Theme <= 2.0 - Path Traversal Vulnerability |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Sat, 30 Aug 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP Local File Inclusion. This issue affects Houzez: from n/a through 4.1.1. | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Favethemes Houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a before 4.1.4. |
| Title | WordPress Houzez Theme <= 4.1.1 - Local File Inclusion Vulnerability | WordPress Houzez Theme < 4.1.4 - Local File Inclusion Vulnerability |
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Favethemes
Favethemes houzez Wordpress Wordpress wordpress |
|
| Vendors & Products |
Favethemes
Favethemes houzez Wordpress Wordpress wordpress |
Thu, 28 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Aug 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP Local File Inclusion. This issue affects Houzez: from n/a through 4.1.1. | |
| Title | WordPress Houzez Theme <= 4.1.1 - Local File Inclusion Vulnerability | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:13:03.898Z
Reserved: 2025-06-04T15:44:03.663Z
Link: CVE-2025-49405
Updated: 2025-08-28T19:05:20.643Z
Status : Deferred
Published: 2025-08-28T13:16:00.063
Modified: 2026-04-28T19:33:05.120
Link: CVE-2025-49405
No data.
OpenCVE Enrichment
Updated: 2026-04-30T07:45:26Z
EUVD