CVE-2025-5117

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above, to elevate their privileges to that of an administrator by creating a package post whose property_package_user_role is set to administrator and then submitting the PayPal registration form.

<p><strong>Property &#8211; Real Estate Directory Listing</strong> is the ultimate WordPress plugin for managing property listings, real estate directories, and classified ads. Whether you&#8217;re building a business directory, a real estate marketplace, or a local classifieds site, this plugin offers all the essential tools for a seamless experience.</p> <p>🚀 <strong>Why Choose Property &#8211; Real Estate Directory Listing?</strong><br /> &#8211; <strong>SEO Optimized</strong>: Structured data, schema markup, and fast performance enhance search engine rankings.<br /> &#8211; <strong>Mobile-Friendly &amp; Responsive</strong>: Works perfectly on all devices.<br /> &#8211; <strong>Customizable &amp; Flexible</strong>: Add custom fields, categories, and filters effortlessly.<br /> &#8211; <strong>Easy Monetization</strong>: Charge users for premium listings with WooCommerce integration.<br /> &#8211; <strong>Fast &amp; Lightweight</strong>: Optimized code ensures high performance.</p> <p>🎯 <strong>Key Features:</strong><br /> ✔ <strong>Advanced Search &amp; Filters</strong> – Helps users find properties quickly.<br /> ✔ <strong>Frontend Submission</strong> – Users can submit and manage listings directly from the frontend.<br /> ✔ <strong>Google Maps &amp; OpenStreetMap Integration</strong> – Display property locations dynamically.<br /> ✔ <strong>CSV Import &amp; Export</strong> – Easily bulk upload or download listings.<br /> ✔ <strong>Ratings &amp; Reviews</strong> – Allow users to review and rate properties.<br /> ✔ <strong>Shortcodes &amp; Widgets</strong> – Display listings anywhere on your site.<br /> ✔ <strong>Multilingual Ready</strong> – Fully compatible with WPML, Loco Translate, and Polylang.<br /> ✔ <strong>Custom Fields &amp; Taxonomies</strong> – Adapt the plugin to your needs.<br /> ✔ <strong>WooCommerce Payment Integration</strong> – Charge for premium listings.<br /> ✔ <strong>Image Gallery &amp; Video Support</strong> – Showcase listings with high-quality images and videos.<br /> ✔ <strong>AJAX-powered Listings</strong> – Fast, dynamic updates without page reloads.</p> <p>🔗 <strong><a href="https://propertypro.e-plugins.com/" rel="nofollow ugc">Live Demo</a></strong> | <strong><a href="https://help.eplug-ins.com/propertypro/" rel="nofollow ugc">Documentation</a></strong> | <strong><a href="http://e-plugins.com/support" rel="nofollow ugc">Support</a></strong></p> <h3>External Services</h3> <p>This plugin integrates with third-party services to provide enhanced functionality:</p> <ul> <li><strong>Google Maps API</strong> – Displays interactive maps. <a href="https://policies.google.com/privacy" rel="nofollow ugc">Privacy Policy</a> </li> <li><strong>OpenStreetMap API</strong> – Free alternative to Google Maps. <a href="https://wiki.osmfoundation.org/wiki/Privacy_Policy" rel="nofollow ugc">Privacy Policy</a> </li> <li><strong>LocationIQ API</strong> – Geolocation and address lookup. <a href="https://locationiq.com/privacy" rel="nofollow ugc">Privacy Policy</a> </li> <li><strong>YouTube &amp; Vimeo</strong> – Embed property listing videos. <a href="https://policies.google.com/privacy" rel="nofollow ugc">YouTube</a> | <a href="https://vimeo.com/privacy" rel="nofollow ugc">Vimeo</a> </li> <li><strong>Fancybox &amp; Colorbox</strong> – Lightbox image effects.</li> </ul> <h3>Support &amp; Feedback</h3> <p>Need help? Visit our <strong><a href="http://e-plugins.com/support" rel="nofollow ugc">Support Page</a></strong> or explore our <strong><a href="https://help.eplug-ins.com/propertypro/" rel="nofollow ugc">Documentation</a></strong>.</p> <p>We appreciate your feedback! If you enjoy using this plugin, please <strong>leave us a review</strong> on WordPress.org. ⭐⭐⭐⭐⭐</p>
WordPress Plugin DirectoryWordPress Plugin Directory
1.43K