What the vulnerability does
01Description
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
Explanation of Vulnerability in Simple Terms
Houzez Login Register versions up to 3.2.5 contain an improper privilege escalation vulnerability. An authenticated user with low privileges can gain high-level access to the site, including the ability to read sensitive data, modify content, and disrupt service. The vulnerability requires only network access and no user interaction from the victim.
What an attacker can do
Read sensitive data, modify site content, and disrupt service availability after gaining elevated privileges.
Potential impact on your site
Any registered user can escalate their account to administrator-level access, compromising site security and data integrity.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities