CVE-2025-9191 Overview
The Houzez theme for WordPress contains a PHP Object Injection vulnerability affecting all versions up to and including 4.1.6. The flaw resides in saved-search-item.php, which deserializes untrusted input without validation. Authenticated attackers with Subscriber-level access or higher can inject arbitrary PHP objects into the application. The vulnerability itself does not trigger direct code execution because no Property-Oriented Programming (POP) chain exists in the vulnerable software. However, if another installed plugin or theme provides a POP chain, attackers can leverage it to delete files, exfiltrate sensitive data, or execute arbitrary code.
Critical Impact
Authenticated Subscriber-level users can inject PHP objects that may lead to file deletion, data disclosure, or remote code execution when a POP chain is available through other installed components.
Affected Products
- Houzez theme for WordPress, all versions up to and including 4.1.6
- WordPress sites running the vulnerable Houzez theme alongside plugins or themes that expose PHP magic method POP chains
- Multi-tenant WordPress environments where Subscriber accounts are freely provisioned
Discovery Timeline
- 2025-11-26 - CVE-2025-9191 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9191
Vulnerability Analysis
The vulnerability is classified as Insecure Deserialization [CWE-502]. The saved-search-item.php file passes attacker-controlled input into PHP's unserialize() function without sanitization or type restriction. This allows an authenticated user to submit crafted serialized data that PHP reconstructs into arbitrary object instances. When those objects are destroyed or interacted with, their magic methods such as __wakeup(), __destruct(), or __toString() execute. The Houzez codebase alone does not ship a usable POP chain, so exploitation depends on gadget classes contributed by other installed WordPress plugins or themes.
Root Cause
The root cause is direct deserialization of untrusted input in the saved search handler. Modern PHP applications should replace unserialize() with structured formats such as JSON or use the allowed_classes option to restrict object instantiation. Houzez did neither, so any Subscriber account becomes a foothold for object injection.
Attack Vector
Exploitation requires network access to the WordPress site and a valid low-privilege account. The attacker authenticates as a Subscriber, then submits a serialized PHP payload through the vulnerable saved search endpoint. The application deserializes the payload and instantiates attacker-chosen classes. If a gadget chain is present in another loaded plugin or theme, the resulting object graph can trigger file operations, database queries, or command execution during PHP's normal lifecycle events.
Refer to the Wordfence Vulnerability Report for additional technical context.
Detection Methods for CVE-2025-9191
Indicators of Compromise
- HTTP POST requests to Houzez saved-search endpoints containing serialized PHP payloads beginning with O:, a:, or s:
- Unexpected file creation, deletion, or modification under wp-content/ following Subscriber account activity
- New or modified WordPress administrator accounts created shortly after saved-search requests
- PHP error log entries referencing __wakeup, __destruct, or class instantiation failures during Houzez requests
Detection Strategies
- Inspect web server logs for requests to saved-search-item.php carrying URL-encoded serialized object markers
- Deploy a Web Application Firewall (WAF) rule that blocks serialized PHP object patterns in Houzez request parameters
- Baseline expected Subscriber behavior and alert on account activity that touches theme or plugin file paths
Monitoring Recommendations
- Enable file integrity monitoring on wp-content/themes/houzez/ and all active plugin directories
- Forward WordPress audit logs and PHP error logs to a centralized SIEM for correlation
- Track newly registered Subscriber accounts that immediately interact with saved-search functionality
How to Mitigate CVE-2025-9191
Immediate Actions Required
- Update the Houzez theme to a version newer than 4.1.6 once the vendor publishes a fix, per the FaveThemes Changelog
- Audit installed plugins and themes for known POP chain gadgets and remove unused components
- Disable open Subscriber registration on sites that do not require it, or enforce administrator approval
- Rotate credentials and review recent Subscriber-level account creations for suspicious activity
Patch Information
Review the FaveThemes Changelog for the fixed release. Apply the vendor patch across staging and production environments, then verify the saved-search-item.php handler no longer calls unserialize() on untrusted input.
Workarounds
- Restrict access to the Houzez saved-search endpoint at the WAF or reverse proxy layer until the patch is applied
- Temporarily disable the Houzez theme on sites where saved searches are not in active use
- Enforce strong role-based access controls and remove unnecessary Subscriber accounts
# Example WAF rule concept (ModSecurity) to block serialized PHP objects
SecRule ARGS "@rx (?i)(^|&)[^=]*=(O|a|s):[0-9]+:" \
"id:1009191,phase:2,deny,status:403,\
msg:'Possible PHP object injection targeting Houzez saved-search endpoint'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.