Input validation vulnerability in Houzez Theme – Functionality 3.2.2

The Houzez Theme, a plugin used with WordPress, has a security issue where hackers can inject code into the system through a parameter called ‘currency_code’. This can happen in any version up to 3.2.2 and is caused by not properly protecting the user’s input and not properly preparing the existing code. This means that attackers with Custom-level access or higher can add their own code to steal sensitive information from the database.

Detected in:

Houzez Theme - Functionality fixed vulnerable versions: >= * <= 3.2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.