CVE-2025-49405 | favethemes Houzez Plugin up to 4.1.1 on WordPress filename control
A vulnerability categorized as problematic has been discovered in favethemes Houzez Plugin up to 4.1.1 on WordPress. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is listed as CVE-2025-49405. The attack may be performed from a remote location. There is no available exploit.