Description
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
* (semver)
Credits
Sammy FORGIT
References
www.exploit-db.com/exploits/23651
www.exploit-db.com/exploits/18987
raw.githubusercontent.com/...bapp/wp_property_upload_exec.rb
wordpress.org/plugins/wp-property/
raw.githubusercontent.com/...bapp/wp_property_upload_exec.rb
www.exploit-db.com/exploits/18987
www.exploit-db.com/exploits/23651
web.archive.org/...-property-shell-upload-vulnerability.html
www.vulncheck.com/...ress-plugin-wp-property-php-file-upload