CVE-2026-57768
Deferred Deferred - Pending Action

Privilege Escalation in Houzez Login Register

Vulnerability report for CVE-2026-57768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
favethemes houzez_login_register From 3.0.0 (inc) to 3.3.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WordPress Houzez Login Register Plugin, versions 3.3.3 and below, contains a high-priority Privilege Escalation vulnerability (CVE-2026-57768). This flaw allows unauthenticated attackers to escalate their low-privilege accounts to higher privileges, potentially gaining full control of the website.

It is classified under OWASP Top 10 A7 (Identification and Authentication Failures) and poses a significant security risk with a CVSS score of 8.2.

Detection Guidance

There is no specific information provided about detection commands or methods to identify this vulnerability on your network or system.

Impact Analysis

This vulnerability can allow attackers to escalate their privileges on a website using the Houzez Login Register Plugin, potentially gaining full control over the site.

Such control could lead to unauthorized changes, data breaches, or complete takeover of the website, severely impacting the security and integrity of your online presence.

Since the vulnerability can be exploited without authentication, it increases the risk of mass exploitation across many websites.

Compliance Impact

This vulnerability can significantly impact compliance with common standards and regulations such as GDPR and HIPAA due to its potential to allow unauthorized access and privilege escalation.

  • GDPR: The vulnerability may lead to unauthorized access to personal data, violating GDPR's requirements for data protection and confidentiality. Under GDPR, organizations must implement appropriate security measures to prevent unauthorized access to personal data. Failure to address this vulnerability could result in non-compliance, leading to hefty fines and legal consequences.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability poses a risk of unauthorized access to sensitive patient data. HIPAA requires strict access controls and safeguards to protect PHI. Exploitation of this vulnerability could lead to breaches of PHI, resulting in violations of HIPAA's Privacy and Security Rules.
  • General Compliance: The vulnerability is classified under OWASP Top 10 A7 (Identification and Authentication Failures), which is a critical area for compliance frameworks. Organizations must ensure robust authentication and authorization mechanisms to comply with various industry standards and regulations.

Immediate remediation is necessary to maintain compliance and avoid potential legal and financial penalties.

Mitigation Strategies

Immediate mitigation steps include updating the Houzez Login Register plugin to a version above 3.3.3 once available.

Since no official patch is currently available, applying the mitigation rule issued by Patchstack to block attacks is advised.

You should also consider seeking assistance from your hosting provider or a developer to implement temporary protections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart