← back
CVE-2023-36529criticalobserved exploitationCWE-89

WordPress Houzez CRM Plugin <= 1.3.4 is vulnerable to SQL Injection

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.9epss 0.7%
from disclosure to weapon
Published on NVDNov 3
VulnCheckJun 28
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
yesVulnCheck
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H