VYPR

Property Pro

by Property Pro

CVEs (2)

  • CVE-2025-5117HigMay 27, 2025
    risk 0.50cvss 8.8epss 0.00

    The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above,…

  • CVE-2006-6029Nov 21, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in vir_Login.asp in Property Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the UserName field.