Cyber Security

WordPress Theme & Plugin Vulnerabilities Exposes Thousands of Sites

Thousands of WordPress sites have been exposed to potential threats due to vulnerabilities in the Houzez theme and WordPress Houzez Login Register plugin.

The flaw is identified as CVE-2024-22303 and CVE-2024-21743. It affects versions up to 3.2.4 and 3.2.5 and is classified as a high-priority issue with a CVSS score of 8.8, indicating significant risk.

CVE-2024-22303 – WordPress Houzez Theme Vulnerability

The vulnerability allows privilege escalation, enabling malicious actors to elevate their access from low-privileged accounts to higher privileges.

This could potentially lead to complete control over the affected website. The issue is categorized under the OWASP Top 10 as A5: Security Misconfiguration.

Patch and Mitigation

Patchstack has released a virtual patch to mitigate this vulnerability until users can update to the fixed version, 3.3.0. Website administrators are strongly advised to update immediately to prevent exploitation.

DetailsInformation
SoftwareHouzez
TypeTheme
Vulnerable Versions<= 3.2.4
Fixed in Version3.3.0
Patch PriorityHigh
CVSS SeverityHigh (8.8)
Published Date17 September 2024

CVE-2024-21743 – WordPress Houzez Login Register Plugin

The vulnerability allows for privilege escalation, potentially enabling attackers to elevate their access from a low-privileged account to higher privileges, which could result in complete control over the affected website.

This issue is categorized under the OWASP Top 10 as A5: Security Misconfiguration.

Download Free Incident Response Plan Template for Your Security Team – Free Download

Patch and Mitigation

Patchstack has provided a virtual patch to mitigate this vulnerability until users can update to the fixed version, 3.3.0. Website administrators must update immediately to prevent potential exploitation.

DetailsInformation
SoftwareHouzez Login Register
TypePlugin
Vulnerable Versions<= 3.2.5
Fixed in Version3.3.0
Patch PriorityHigh
CVSS SeverityHigh (8.8)
Published Date17 September 2024

Risks and Recommendations

The vulnerability’s high severity suggests it could be widely exploited if not addressed promptly. Administrators should prioritize updating their sites to version 3.3.0 or later and consider using Patchstack for automatic mitigation.

This incident highlights the importance of maintaining up-to-date software and implementing robust security measures to protect digital assets from evolving threats.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14-day free trial

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

3 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago