PT-2026-54629 · WordPress · Houzez Property Feed

·

CVE-2026-13357

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Houzez Property Feed versions prior to 2.5.47
Description The plugin is susceptible to SQL Injection, a technique where malicious SQL statements are inserted into entry fields for execution. The issue occurs in the prepare items() method of the Houzez Property Feed Admin Logs Export Table and Houzez Property Feed Admin Logs Import Table classes. Authenticated attackers with Administrator-level access or higher can exploit this by manipulating the orderby and order parameters via $ GET requests. Because these values are only processed with sanitize text field() and concatenated into the SQL string before the $wpdb->prepare() function is called, the ORDER BY clause remains insecure. This allows the attacker to append additional SQL queries to extract sensitive information from the database.
Recommendations Update to a version later than 2.5.46.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13357

Affected Products

Houzez Property Feed