WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress Wp-property Wp-property wp-property Wordpress Plugin |
|
Vendors & Products |
Wordpress
Wordpress wordpress Wp-property Wp-property wp-property Wordpress Plugin |
Wed, 06 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution. | |
Title | WordPress Plugin WP-Property <= 1.35.0 PHP File Upload | |
Weaknesses | CWE-434 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-05T20:06:43.138Z
Updated: 2025-08-06T13:55:20.302Z
Reserved: 2025-08-05T15:59:41.505Z
Link: CVE-2012-10027

Updated: 2025-08-06T13:55:06.412Z

Status : Awaiting Analysis
Published: 2025-08-05T20:15:33.560
Modified: 2025-08-06T14:15:35.633
Link: CVE-2012-10027

No data.