PT-2025-18756 · WordPress · Homey

Ayoub Nouri

·

Published

2025-05-02

·

Updated

2025-05-02

·

CVE-2025-1327

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Homey theme for WordPress versions up to, and including, 2.4.4
Description The issue allows authenticated attackers with Subscriber-level access and above to delete other users' accounts due to missing validation on a user-controlled key in the homey delete user account action.
Recommendations For versions up to, and including, 2.4.4, consider disabling the homey delete user account action until a patch is available to prevent unauthorized account deletion. Restrict access to this action to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-1327

Affected Products

Homey