CVE-2025-5117
Published
CVSS v3
8.8
HIGH
CVSS v2
N/A
Affected
1
PROJECT
Description
The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above, to elevate their privileges to that of an administrator by creating a package post whose property_package_user_role is set to administrator and then submitting the PayPal registration form.
<p><strong>Property – Real Estate Directory Listing</strong> is the ultimate WordPress plugin for managing property listings, real estate directories, and classified ads. Whether you’re building a business directory, a real estate marketplace, or a local classifieds site, this plugin offers all the essential tools for a seamless experience.</p>
<p>🚀 <strong>Why Choose Property – Real Estate Directory Listing?</strong><br />
– <strong>SEO Optimized</strong>: Structured data, schema markup, and fast performance enhance search engine rankings.<br />
– <strong>Mobile-Friendly & Responsive</strong>: Works perfectly on all devices.<br />
– <strong>Customizable & Flexible</strong>: Add custom fields, categories, and filters effortlessly.<br />
– <strong>Easy Monetization</strong>: Charge users for premium listings with WooCommerce integration.<br />
– <strong>Fast & Lightweight</strong>: Optimized code ensures high performance.</p>
<p>🎯 <strong>Key Features:</strong><br />
✔ <strong>Advanced Search & Filters</strong> – Helps users find properties quickly.<br />
✔ <strong>Frontend Submission</strong> – Users can submit and manage listings directly from the frontend.<br />
✔ <strong>Google Maps & OpenStreetMap Integration</strong> – Display property locations dynamically.<br />
✔ <strong>CSV Import & Export</strong> – Easily bulk upload or download listings.<br />
✔ <strong>Ratings & Reviews</strong> – Allow users to review and rate properties.<br />
✔ <strong>Shortcodes & Widgets</strong> – Display listings anywhere on your site.<br />
✔ <strong>Multilingual Ready</strong> – Fully compatible with WPML, Loco Translate, and Polylang.<br />
✔ <strong>Custom Fields & Taxonomies</strong> – Adapt the plugin to your needs.<br />
✔ <strong>WooCommerce Payment Integration</strong> – Charge for premium listings.<br />
✔ <strong>Image Gallery & Video Support</strong> – Showcase listings with high-quality images and videos.<br />
✔ <strong>AJAX-powered Listings</strong> – Fast, dynamic updates without page reloads.</p>
<p>🔗 <strong><a href="https://propertypro.e-plugins.com/" rel="nofollow ugc">Live Demo</a></strong> | <strong><a href="https://help.eplug-ins.com/propertypro/" rel="nofollow ugc">Documentation</a></strong> | <strong><a href="http://e-plugins.com/support" rel="nofollow ugc">Support</a></strong></p>
<h3>External Services</h3>
<p>This plugin integrates with third-party services to provide enhanced functionality:</p>
<ul>
<li><strong>Google Maps API</strong> – Displays interactive maps. <a href="https://policies.google.com/privacy" rel="nofollow ugc">Privacy Policy</a> </li>
<li><strong>OpenStreetMap API</strong> – Free alternative to Google Maps. <a href="https://wiki.osmfoundation.org/wiki/Privacy_Policy" rel="nofollow ugc">Privacy Policy</a> </li>
<li><strong>LocationIQ API</strong> – Geolocation and address lookup. <a href="https://locationiq.com/privacy" rel="nofollow ugc">Privacy Policy</a> </li>
<li><strong>YouTube & Vimeo</strong> – Embed property listing videos. <a href="https://policies.google.com/privacy" rel="nofollow ugc">YouTube</a> | <a href="https://vimeo.com/privacy" rel="nofollow ugc">Vimeo</a> </li>
<li><strong>Fancybox & Colorbox</strong> – Lightbox image effects.</li>
</ul>
<h3>Support & Feedback</h3>
<p>Need help? Visit our <strong><a href="http://e-plugins.com/support" rel="nofollow ugc">Support Page</a></strong> or explore our <strong><a href="https://help.eplug-ins.com/propertypro/" rel="nofollow ugc">Documentation</a></strong>.</p>
<p>We appreciate your feedback! If you enjoy using this plugin, please <strong>leave us a review</strong> on WordPress.org. ⭐⭐⭐⭐⭐</p>