Input validation vulnerability in Houzez 4.0.4

The Houzez theme for WordPress has a security issue called Local File Inclusion in versions 4.0.4 and below. This means that people who are not logged in can access and run any files they want on the server, including PHP code. This can be used to get around security measures, access private information, or run code even if the file type is typically considered safe, like images.

Detected in:

Houzez open vulnerable versions: >= * <= 4.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.