CVE-2025-6934 is a critical privilege escalation vulnerability affecting all versions up to 1.7.5 of the Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme. This flaw allows unauthenticated attackers to register new user accounts and arbitrarily assign themselves any role, including Administrator, due to a lack of role restriction during registration. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a high impact on confidentiality, integrity, and availability, requiring no user interaction or authentication to exploit. While not yet in CISA's KEV catalog, Nuclei templates for this exploit exist, and it has garnered community discussion, indicating a potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wpopal | Opal Estate Pro – Property Management And Submission | >= 0, <= 1.7.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.