CVE-2023-26009

CRITICAL EXPLOITED IN THE WILD

Houzez Login Register <2.6.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-26009 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.

Scores

CVSS v3 9.8
EPSS 0.0273
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2023-02-23
InTheWild.io 2023-02-27
CWE
CWE-269
Status published
Products (1)
Favethemes/Houzez Login Register < 2.6.3
Published May 17, 2024
Tracked Since Feb 18, 2026