Skip to main content

CVE-2025-9191: Houzez WordPress Theme RCE Vulnerability

CVE-2025-9191 is a PHP Object Injection flaw in Houzez WordPress theme that could enable remote code execution when combined with POP chains. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2025-9191 Overview

The Houzez theme for WordPress contains a PHP Object Injection vulnerability affecting all versions up to and including 4.1.6. The flaw resides in saved-search-item.php, which deserializes untrusted input without validation. Authenticated attackers with Subscriber-level access or higher can inject arbitrary PHP objects into the application. The vulnerability itself does not trigger direct code execution because no Property-Oriented Programming (POP) chain exists in the vulnerable software. However, if another installed plugin or theme provides a POP chain, attackers can leverage it to delete files, exfiltrate sensitive data, or execute arbitrary code.

Critical Impact

Authenticated Subscriber-level users can inject PHP objects that may lead to file deletion, data disclosure, or remote code execution when a POP chain is available through other installed components.

Affected Products

  • Houzez theme for WordPress, all versions up to and including 4.1.6
  • WordPress sites running the vulnerable Houzez theme alongside plugins or themes that expose PHP magic method POP chains
  • Multi-tenant WordPress environments where Subscriber accounts are freely provisioned

Discovery Timeline

  • 2025-11-26 - CVE-2025-9191 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9191

Vulnerability Analysis

The vulnerability is classified as Insecure Deserialization [CWE-502]. The saved-search-item.php file passes attacker-controlled input into PHP's unserialize() function without sanitization or type restriction. This allows an authenticated user to submit crafted serialized data that PHP reconstructs into arbitrary object instances. When those objects are destroyed or interacted with, their magic methods such as __wakeup(), __destruct(), or __toString() execute. The Houzez codebase alone does not ship a usable POP chain, so exploitation depends on gadget classes contributed by other installed WordPress plugins or themes.

Root Cause

The root cause is direct deserialization of untrusted input in the saved search handler. Modern PHP applications should replace unserialize() with structured formats such as JSON or use the allowed_classes option to restrict object instantiation. Houzez did neither, so any Subscriber account becomes a foothold for object injection.

Attack Vector

Exploitation requires network access to the WordPress site and a valid low-privilege account. The attacker authenticates as a Subscriber, then submits a serialized PHP payload through the vulnerable saved search endpoint. The application deserializes the payload and instantiates attacker-chosen classes. If a gadget chain is present in another loaded plugin or theme, the resulting object graph can trigger file operations, database queries, or command execution during PHP's normal lifecycle events.

Refer to the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2025-9191

Indicators of Compromise

  • HTTP POST requests to Houzez saved-search endpoints containing serialized PHP payloads beginning with O:, a:, or s:
  • Unexpected file creation, deletion, or modification under wp-content/ following Subscriber account activity
  • New or modified WordPress administrator accounts created shortly after saved-search requests
  • PHP error log entries referencing __wakeup, __destruct, or class instantiation failures during Houzez requests

Detection Strategies

  • Inspect web server logs for requests to saved-search-item.php carrying URL-encoded serialized object markers
  • Deploy a Web Application Firewall (WAF) rule that blocks serialized PHP object patterns in Houzez request parameters
  • Baseline expected Subscriber behavior and alert on account activity that touches theme or plugin file paths

Monitoring Recommendations

  • Enable file integrity monitoring on wp-content/themes/houzez/ and all active plugin directories
  • Forward WordPress audit logs and PHP error logs to a centralized SIEM for correlation
  • Track newly registered Subscriber accounts that immediately interact with saved-search functionality

How to Mitigate CVE-2025-9191

Immediate Actions Required

  • Update the Houzez theme to a version newer than 4.1.6 once the vendor publishes a fix, per the FaveThemes Changelog
  • Audit installed plugins and themes for known POP chain gadgets and remove unused components
  • Disable open Subscriber registration on sites that do not require it, or enforce administrator approval
  • Rotate credentials and review recent Subscriber-level account creations for suspicious activity

Patch Information

Review the FaveThemes Changelog for the fixed release. Apply the vendor patch across staging and production environments, then verify the saved-search-item.php handler no longer calls unserialize() on untrusted input.

Workarounds

  • Restrict access to the Houzez saved-search endpoint at the WAF or reverse proxy layer until the patch is applied
  • Temporarily disable the Houzez theme on sites where saved searches are not in active use
  • Enforce strong role-based access controls and remove unnecessary Subscriber accounts
bash
# Example WAF rule concept (ModSecurity) to block serialized PHP objects
SecRule ARGS "@rx (?i)(^|&)[^=]*=(O|a|s):[0-9]+:" \
  "id:1009191,phase:2,deny,status:403,\
   msg:'Possible PHP object injection targeting Houzez saved-search endpoint'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.