Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Houzez theme to the latest available version (at least 4.1.4).
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28301 | Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1. |
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Premium Age Verification / Restriction for WordPress age-restriction allows Blind SQL Injection.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through <= 3.0.2. | Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1. |
| Title | WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - SQL Injection Vulnerability | WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerability |
| Weaknesses | CWE-862 | |
| References |
|
Thu, 23 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| References |
|
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1. | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Premium Age Verification / Restriction for WordPress age-restriction allows Blind SQL Injection.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through <= 3.0.2. |
| Title | WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerability | WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - SQL Injection Vulnerability |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Favethemes
Favethemes houzez Wordpress Wordpress wordpress |
|
| Vendors & Products |
Favethemes
Favethemes houzez Wordpress Wordpress wordpress |
Wed, 20 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1. | |
| Title | WordPress Houzez Theme <= 4.1.1 - Broken Access Control Vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:13:04.018Z
Reserved: 2025-06-04T15:44:12.380Z
Link: CVE-2025-49406
Updated: 2025-08-20T18:06:04.259Z
Status : Deferred
Published: 2025-08-20T08:15:35.703
Modified: 2026-04-28T19:33:05.240
Link: CVE-2025-49406
No data.
OpenCVE Enrichment
Updated: 2026-04-30T16:00:13Z
EUVD