CVE-2025-6934 Information
Description
The Opal Estate Pro – Property Management and Submission plugin for WordPress used by the FullHouse - Real Estate Responsive WordPress Theme is vulnerable to privilege escalation via in all versions up to and including 1.7.5. This is due to a lack of role restriction during registration in the ‘on_regiser_user’ function. This makes it possible for unauthenticated attackers to arbitrarily choose the role including the Administrator role assigned when registering.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://plugins.trac.wordpress.org/browser/opal-estate-pro/trunk/inc/user/class-opalestate-user.php#L228 https://plugins.trac.wordpress.org/browser/opal-estate-pro/trunk/inc/user/class-opalestate-user.php#L235 https://themeforest.net/item/fullhouse-real-estate-responsive-wordpress-theme/16179481 https://www.wordfence.com/threat-intel/vulnerabilities/id/5d7b75a4-67b4-4347-91a6-dbf98da5ceaf?source=cve
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Related CNNVD
CNNVD-202507-020 (Published: 2025-07-01)
Share on: