Description
The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6223 | The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user. |
References
History
Fri, 07 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user. | |
| Title | Homey <= 2.4.3 - Limited Authentication Bypass due to Missing Empty Value Check | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:33:33.767Z
Reserved: 2025-01-27T13:37:29.548Z
Link: CVE-2025-0749
Updated: 2025-03-07T16:32:05.938Z
Status : Deferred
Published: 2025-03-07T02:15:37.820
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-0749
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD