PT-2025-48135 · WordPress · Houzez

Alex Thomas

·

Published

2025-11-26

·

Updated

2025-11-26

·

CVE-2025-9163

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Houzez theme for WordPress versions prior to 4.1.7
Description The Houzez theme for WordPress is susceptible to Stored Cross-Site Scripting through SVG file uploads. This is due to inadequate input sanitization and output escaping within the houzez property img upload() and houzez property attachment upload() functions. This allows unauthenticated attackers to inject arbitrary web scripts into pages, which will execute when a user accesses the SVG file.
Recommendations Update the Houzez theme to version 4.1.7 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-9163

Affected Products

Houzez