First published: Wed Dec 20 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Houzez | <2.8.3 |
Update to 2.8.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29432 is classified as a critical SQL injection vulnerability.
To fix CVE-2023-29432, you should update the Favethemes Houzez theme to version 2.8.3 or later.
CVE-2023-29432 affects all versions of the Houzez theme prior to 2.8.3.
CVE-2023-29432 is an SQL Injection vulnerability that allows attackers to manipulate SQL queries.
Yes, CVE-2023-29432 can be exploited remotely without authentication, posing a significant risk.