Threat groups are actively exploiting two critical-severity vulnerabilities in the Houzez theme and plugin for WordPress. The $69 add-on theme offers easy listing management and smooth customer interface. The plugin is used by roughly 35,000 websites within the real estate sector. The first vulnerability, tracked as CVE-2023-26540, has a critical rating and is a security misconfiguration that allows privilege escalation without authentication; the vulnerability can be exploited remotely. The second flaw, tracked as CVE-2023-26009, also received a critical rating and allows unauthenticated attackers to perform privilege escalation on sites which have deployed the Housez plugin.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security