Description
Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.
Published: 2026-07-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress Houzez Login Register plugin contains an improper authorization flaw that allows users with limited permissions to obtain elevated rights. The bug enables a privilege escalation path whereby a non‑administrator can gain administrative capabilities, such as modifying content, adding or deleting users, and changing site configurations. This weakness falls under CWE‑266, describing improper management of authorized identities.

Affected Systems

Any WordPress site running Favethemes Houzez Login Register version 3.3.3 or earlier is affected; no official patch version is documented in the CVE payload.

Risk and Exploitability

The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates an overall low likelihood of exploitation at the present time, and the flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector requires an attacker to already have some level of access to the site or to manipulate internal permission assignments. No public exploit has been disclosed, but the risk remains if the vulnerable plugin is in use and unpatched.

Generated by OpenCVE AI on August 1, 2026 at 10:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Houzez Login Register plugin to the latest vendor release once a fix is available.
  • If no update is available, temporarily deactivate or uninstall the plugin to prevent privilege escalation until a secure version is released.
  • Audit user accounts to identify and remove any unauthorized or newly elevated accounts that may have been created during the vulnerability window.

Generated by OpenCVE AI on August 1, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Favethemes
Favethemes houzez Login Register
Wordpress
Wordpress wordpress
Vendors & Products Favethemes
Favethemes houzez Login Register
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.
Title WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Favethemes Houzez Login Register
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:07:21.069Z

Reserved: 2026-06-25T08:04:47.959Z

Link: CVE-2026-57768

cve-icon Vulnrichment

Updated: 2026-07-13T14:07:15.417Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment