Exploit
Opal Estate Pro WordPress plugin <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
CVE: CVE-2025-6934
PT-Identifier: PT-2025-27507
Vendor: wpopal
Product: Opal Estate Pro – Property Management and Submission
CVSS: 9.8
Credits: Alyudin Nafiie
Description:
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.
References:
• https://dbugs.ptsecurity.com/vulnerability/CVE-2025-6934
• https://www.wordfence.com/threat-intel/vulnerabilities/id/5d7b75a4-67b4-4347-91a6-dbf98da5ceaf?source=cve
• https://themeforest.net/item/fullhouse-real-estate-responsive-wordpress-theme/16179481
• https://plugins.trac.wordpress.org/browser/opal-estate-pro/trunk/inc/user/class-opalestate-user.php#L228
• https://plugins.trac.wordpress.org/browser/opal-estate-pro/trunk/inc/user/class-opalestate-user.php#L235
Exploit: https://github.com/MejbanKadir/CVE-2025-6934-PoC
#dbugs_vuln
Post summary
The post confirms a CVE-2025-6934 privilege‑escalation in the Opal Estate Pro WordPress plugin, gives technical details, and provides a working exploit/Poc repository.