Houzez <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation
2024-09-17 00:00
lucStrategic Overview
Vulnerability Overview
The Houzez theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the houzez_ajax_password_reset function not properly verifying a user's identity prior to reseting a password. This makes it possible for authenticated attackers, with subscriber-level access and above, to gain administrative access to vulnerable sites.
Technical Analysis
REMEDIATION: Update to version 3.3.0, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C