Description
WordPress Plugin WP-Property-WordPress Powered Real Estate and Property Management is prone to an information disclosure vulnerability because it fails to properly sanitize user-supplied input. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin WP-Property-WordPress Powered Real Estate and Property Management version 1.38.3.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.38.4 or latest
References
Related Vulnerabilities
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3231)
phpBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1627)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)
WordPress Plugin Category Order and Taxonomy Terms Order PHP Object Injection (1.5.2.2)