CVE-2025-6934Exploit

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-23); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-23: 1Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-03-23: 1Technical Details · 2026-03-23: 103-2308-20
Signal classification2 categories
Exploit
150.0%
General
150.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-231
Exploit1
2026-08-201
General1
Full discourse2 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2023-46604 CVE-2026-61241 CVE-2025-6934 CVE-2025-24893 CVE-2026-60137 CVE-2026-63030 ..🧵👇

    Post summary

    The post simply lists several critical CVE identifiers without any detailed context or actionable information.

    1001091
    37 followersView on X
  • dbugs@ptdbugs
    Exploit

    Opal Estate Pro WordPress plugin <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user' CVE: CVE-2025-6934 PT-Identifier: PT-2025-27507 Vendor: wpopal Product: Opal Estate Pro – Property Management and Submission CVSS: 9.8 Credits: Alyudin Nafiie Description: The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2025-6934 • https://www.wordfence.com/threat-intel/vulnerabilities/id/5d7b75a4-67b4-4347-91a6-dbf98da5ceaf?source=cve • https://themeforest.net/item/fullhouse-real-estate-responsive-wordpress-theme/16179481 • https://plugins.trac.wordpress.org/browser/opal-estate-pro/trunk/inc/user/class-opalestate-user.php#L228 • https://plugins.trac.wordpress.org/browser/opal-estate-pro/trunk/inc/user/class-opalestate-user.php#L235 Exploit: https://github.com/MejbanKadir/CVE-2025-6934-PoC #dbugs_vuln

    Post summary

    The post confirms a CVE-2025-6934 privilege‑escalation in the Opal Estate Pro WordPress plugin, gives technical details, and provides a working exploit/Poc repository.

    0000089
    733 followersView on X

Explore more