Description
WordPress Plugin WP-Property-WordPress Powered Real Estate and Property Management is prone to an information disclosure vulnerability because it fails to properly sanitize user-supplied input. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin WP-Property-WordPress Powered Real Estate and Property Management version 1.38.3.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.38.4 or latest
References
Related Vulnerabilities
WebLogic CVE-2019-2650 Vulnerability (CVE-2019-2650)
WordPress Plugin Photo Gallery-Image Gallery by Ape Cross-Site Scripting (1.6.14)
MySQL Other Vulnerability (CVE-2010-3839)
WordPress 4.8.x Cross-Domain Flash Injection Vulnerability (4.8 - 4.8.4)
WordPress Plugin Email Users Cross-Site Request Forgery (4.8.3)