CVE-2025-53198 is a high-severity Local File Inclusion (LFI) vulnerability affecting favethemes Houzez versions up to and including 4.0.4. This flaw, stemming from improper control of filename inclusion, could allow an unauthenticated attacker to include arbitrary files on the server. Rated 8.1 HIGH on the CVSS scale, exploitation requires high attack complexity but could lead to significant impact on confidentiality, integrity, and availability. While listed as "Active" on some internal watchlists, there is currently no evidence of active exploitation in the wild, and no public exploits or community discussion have been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 4.0.4CPE match | cpe:2.3:a:favethemes:houzez:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.