Two critical severity vulnerabilities are being actively exploited by attackers in a WordPress plugin theme called Houzez. This theme is a premium plugin often used to create websites for organisations in the real estate industry. Houzez is a theme produced by the vendor ThemeForest, who fixed the first of these vulnerabilities in August 2022, and the other in November 2022. However, many websites have not patched their systems by applying the latest security upgrades are therefore vulnerable to attack. WordPress security solutions organisation Patchstack have published an article to warn users of these vulnerabilities that are actively being exploited in the wild.
The first vulnerability is tracked as CVE-2023-26009 and has a critical severity rating with a CVSS base score of 9.8/10. This privilege escalation vulnerability is found in the WordPress Houzez Login Register Plugin in versions 2.6.3 and older. The second vulnerability is also a privilege escalation vulnerability tracked as CVE-2023-26540. This flaw is also of critical severity, with a CVSS base score of 9.8. This vulnerability occurs in the WordPress Houzez Theme of versions 2.7.1 and before.
The theme and plugin both have registration functionality that allows a user to provide the role they want to sign up with. Attackers can exploit these vulnerabilities through a malicious endpoint request for account creation where they choose to create an administrator account to immediately receive administrator privileges. This is possible due to errors in the validation checks on the server side. A successful exploit of these flaws could allow the attacker to take full control of the website. With these privileges the attacker can go on to install a malicious plugin that contains a backdoor capable of executing commands, injecting advertisements, and redirecting visitors to malicious sites.
Although these flaws have been patched since they were first identified in 2022, attackers are actively exploiting them in the wild. Security updates and patches should always be applied as soon as possible after their release for all software to ensure the security of all systems and devices. To patch these flaws, WordPress Houzez Login Register Plugin needs to be upgraded to version 2.6.4 or later, and WordPress Houzez Theme needs to be upgraded to version 1.7.2 or later.
“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”
Aim Ltd Chief Technology Officer (CTO)