CVE-2025-49407

Incorrect Privilege Assignment vulnerability in favethemes Premium SEO Pack premium-seo-pack allows Privilege Escalation.This issue affects Premium SEO Pack: from n/a through <= 3.3.2.
Configurations

No configuration.

History

23 Apr 2026, 15:31

Type Values Removed Values Added
Summary (en) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1. (en) Incorrect Privilege Assignment vulnerability in favethemes Premium SEO Pack premium-seo-pack allows Privilege Escalation.This issue affects Premium SEO Pack: from n/a through <= 3.3.2.
References
  • {'url': 'https://patchstack.com/database/wordpress/theme/houzez/vulnerability/wordpress-houzez-theme-4-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/premium-seo-pack/vulnerability/wordpress-premium-seo-pack-plugin-3-3-2-privilege-escalation-vulnerability?_s_id=cve -
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 8.8
CWE CWE-79 CWE-266

28 Aug 2025, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-28 13:16

Updated : 2026-04-23 15:31


NVD link : CVE-2025-49407

Mitre link : CVE-2025-49407

CVE.ORG link : CVE-2025-49407


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment