Junglewise Threat Intelligence

CVE-2026-57768: favethemes Houzez Login Register privilege escalation

CVE-2026-57768 · Severity: high · CVSS 8.2 · Published 2026-07-13

Executive brief

The Houzez Login Register plugin for WordPress, which manages user registration and authentication for real estate websites, contains a security flaw that allows unauthorized users to gain elevated permissions. An attacker could exploit this to upgrade their account privileges, potentially gaining administrative control over the website. This could lead to unauthorized access to sensitive customer data, site defacement, or a complete takeover of the web operations.

Technical details

An Incorrect Privilege Assignment vulnerability (CWE-266) exists in the favethemes Houzez Login Register plugin (houzez-login-register) for WordPress. The flaw allows a remote, unauthenticated attacker to escalate their privileges on the affected site. According to the CVSS vector, the attack is low complexity and requires no user interaction. By exploiting this vulnerability, an attacker can gain higher-level permissions, potentially reaching administrative status. As of the advisory date, no official patch has been released by the vendor, and the vulnerability affects all versions through 3.3.3.

Affected products

  • favethemes Houzez Login Register <= 3.3.3

Timeline

  • 2024-10-02: other: Vulnerability reported by researcher to Patchstack
  • 2026-07-08: advisory: Patchstack published advisory details
  • 2026-07-13: disclosed: CVE published to NVD dataset

References