The Property plugin for WordPress is vulnerable to...
High severity
Unreviewed
Published
May 27, 2025
to the GitHub Advisory Database
•
Updated May 27, 2025
Description
Published by the National Vulnerability Database
May 27, 2025
Published to the GitHub Advisory Database
May 27, 2025
Last updated
May 27, 2025
The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above, to elevate their privileges to that of an administrator by creating a package post whose property_package_user_role is set to administrator and then submitting the PayPal registration form.
References