WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp-property Wp-property wp-property Wordpress Plugin |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp-property Wp-property wp-property Wordpress Plugin |
Wed, 06 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution. | |
| Title | WordPress Plugin WP-Property <= 1.35.0 PHP File Upload | |
| Weaknesses | CWE-434 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-05T20:06:43.138Z
Updated: 2025-08-06T13:55:20.302Z
Reserved: 2025-08-05T15:59:41.505Z
Link: CVE-2012-10027
Updated: 2025-08-06T13:55:06.412Z
Status : Awaiting Analysis
Published: 2025-08-05T20:15:33.560
Modified: 2025-08-06T14:15:35.633
Link: CVE-2012-10027
No data.