Impact
The WordPress Houzez Login Register plugin contains an improper authorization flaw that allows users with limited permissions to obtain elevated rights. The bug enables a privilege escalation path whereby a non‑administrator can gain administrative capabilities, such as modifying content, adding or deleting users, and changing site configurations. This weakness falls under CWE‑266, describing improper management of authorized identities.
Affected Systems
Any WordPress site running Favethemes Houzez Login Register version 3.3.3 or earlier is affected; no official patch version is documented in the CVE payload.
Risk and Exploitability
The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates an overall low likelihood of exploitation at the present time, and the flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector requires an attacker to already have some level of access to the site or to manipulate internal permission assignments. No public exploit has been disclosed, but the risk remains if the vulnerable plugin is in use and unpatched.
OpenCVE Enrichment