N/A
2025-11-26< 4.1.7
Houzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved Search
Minimum safe version
4.2.0
Update to 4.2.0 or later to address 17 fixable vulnerabilities
Houzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved Search
Houzez <= 4.1.6 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
CVE-2025-62053
CVE-2025-49952
CVE-2025-49405
CVE-2025-49407
CVE-2025-49406
CVE-2025-53997
CVE-2025-53198
CVE-2025-24747
CVE-2025-24754
CVE-2024-22303
CVE-2024-43244
Houzez < 1.8.4 - Unauthenticated Cross-Site Scripting (XSS)
CVE-2023-29432
CVE-2023-26540
Houzez <= 1.8.3 - Reflected Cross-Site Scripting
WordPress Houzez theme <= 1.8.3 - Unauthenticated Cross-Site Scripting (XSS) vulnerability