Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Houzez theme to the latest available version (at least 4.1.4).
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26007 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1. |
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 | |
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Privilege Assignment vulnerability in favethemes Premium SEO Pack premium-seo-pack allows Privilege Escalation.This issue affects Premium SEO Pack: from n/a through <= 3.3.2. | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1. |
| Title | WordPress Premium SEO Pack Plugin <= 3.3.2 - Privilege Escalation Vulnerability | WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerability |
| Weaknesses | CWE-79 | |
| References |
|
Thu, 23 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
|
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1. | Incorrect Privilege Assignment vulnerability in favethemes Premium SEO Pack premium-seo-pack allows Privilege Escalation.This issue affects Premium SEO Pack: from n/a through <= 3.3.2. |
| Title | WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerability | WordPress Premium SEO Pack Plugin <= 3.3.2 - Privilege Escalation Vulnerability |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Favethemes
Favethemes houzez Wordpress Wordpress wordpress |
|
| Vendors & Products |
Favethemes
Favethemes houzez Wordpress Wordpress wordpress |
Thu, 28 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Aug 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1. | |
| Title | WordPress Houzez Theme <= 4.1.1 - Cross Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:13:03.578Z
Reserved: 2025-06-04T15:44:12.381Z
Link: CVE-2025-49407
Updated: 2025-08-28T19:03:39.640Z
Status : Deferred
Published: 2025-08-28T13:16:00.273
Modified: 2026-04-28T19:33:05.360
Link: CVE-2025-49407
No data.
OpenCVE Enrichment
Updated: 2026-04-30T07:45:26Z
EUVD