Favethemes develops a focused set of real-estate and property-management WordPress plugins, notably Homey and Houzez, that extend WordPress functionality for rental and sales platforms. The observed vulnerabilities cluster around access-control and input-validation weaknesses, including SQL injection, authorization bypass through user-controlled keys, and missing authorization checks, which are characteristic of web applications handling sensitive property and transaction data.
The number and severity of CVEs published that impact products developed by Favethemes over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51800CRITICAL Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1. | Apr 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-26540CRITICAL Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1. | May 17, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-12281CRITICAL The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new ac | Mar 5, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-49407HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a th | Aug 28, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-36529CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issu | Nov 3, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-62053HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/ | Nov 6, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-49406HIGH Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1. | Aug 20, 2025 | 8.5 | 26 | NO | NO |
CVE-2024-22303HIGH Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4. | Sep 17, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-29432CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Re | Dec 20, 2023 | 9.8 | 26 | NO | NO |
CVE-2025-53198HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez allows PHP Local File Inclusion.Th | Aug 20, 2025 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Favethemes.
Media articles that mention a CVE ID that affects a product developed by Favethemes — matched by CVE ID, not by vendor name.