CVE-2012-10027: Wp-Property WordPress Plugin
Critical severity, CVSS 9.3. EPSS: 1.9% chance of exploitation in the next 30 days.
WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
Affected products
- Wp-Property WordPress Plugin: up to and including 1.35.0
Published 2025-08-05. Last modified 2026-06-16.