CVE-2025-62057

7.1

favethemes · Houzez Theme - Functionality

A stored cross-site scripting (XSS) vulnerability exists in the Houzez Theme - Functionality plugin, allowing unauthenticated attackers to execute arbitrary scripts in a user's browser session.

Executive summary

The Houzez Theme - Functionality plugin for WordPress is vulnerable to cross-site scripting, which could allow an unauthenticated attacker to compromise user sessions.

Vulnerability

This is a cross-site scripting (CWE-79) vulnerability occurring within the houzez-theme-functionality plugin. The flaw allows an unauthenticated attacker to inject malicious scripts into web pages viewed by other users.

Business impact

Successful exploitation of this vulnerability could lead to the theft of session cookies, unauthorized actions performed on behalf of authenticated users, or the redirection of users to malicious websites. Given the CVSS score of 7.1, this is a high-severity issue that poses a significant risk to site integrity and visitor security.

Remediation

Immediate Action: Since a specific patch version is currently unconfirmed, administrators should monitor the official Patchstack database and the vendor website for the release of version 4.2.0 or later.

Proactive Monitoring: Security teams should review web server access logs for anomalous requests containing script tags or suspicious URL parameters targeting the Houzez plugin.

Compensating Controls: Deploy a Web Application Firewall (WAF) with robust XSS protection rules to filter and block malicious input before it reaches the vulnerable plugin functionality.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a significant risk to the security of the WordPress installation and its users. Organizations utilizing the Houzez Theme - Functionality plugin must prioritize monitoring for vendor updates and apply the fix immediately upon release to prevent potential account takeover and unauthorized session hijacking.

More favethemes CVEs

Sources

Originally found and disclosed by João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program, per the CVE Program record.