HomeSecuritySecurity vulnerabilities in Houzez WordPress Theme and Plugin

Security vulnerabilities in Houzez WordPress Theme and Plugin

Researchers discovered two security in the Houzez WordPress theme and its corresponding Login Register plugin, which are widely used in the real estate sector.

Houzez WordPress Plugin Theme vulnerabilities

The two vulnerabilities were discovered by PatchStack and could allow unauthorized users to gain more privileges, putting entire WordPress sites at risk. Fortunately, both vulnerabilities have been patched.

See also: WordPress will require 2FA from plugin developers

The first vulnerability, tracked as CVE-2024-22303, was found in the Houzez theme and could allow malicious users to gain elevated privileges by executing specific HTTP requests. It results from inadequate authorization checks in the code that processes user input. Specifically, the function responsible for password resets did not check whether the user requesting the reset was the account owner. This means that anyone could change passwords.

The second vulnerability in the Houzez Login Register plugin is tracked as CVE-2024-21743 and allows unauthorized users to modify the email addresses associated with any account user. This could lead to account theft. The plugin's function for updating user information lacks proper checks, allowing attackers to exploit it.

The vendor has released updates for both the Houzez WordPress theme and the Login Register plugin. Users are urged to upgrade to version 3.3.0 or later.

See also: LiteSpeed ​​Cache Vulnerability: 6 million WordPress sites at risk

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Security vulnerabilities in Houzez WordPress Theme and Plugin
Security vulnerabilities in Houzez WordPress Theme and Plugin

Additionally, an unsecured WordPress site canundermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

See also: Modern Events Calendar – WordPress: Hackers target vulnerability

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers  ’ trust , preserving your company’s reputation, and staying on top of the competition.

Source: www.infosecurity-magazine.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS