The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.
PoC: CVE-2025-6934
CVE-2025-6934 POC
PoC: CVE-2025-6934-PoC
CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro
PoC: CVE-2025-6934
This repository contains a Proof of Concept (PoC) exploit for CVE-2025-6934, a critical vulnerability in WordPress Plugin: Opal Estate Pro <= 1.7.5, allowing unauthenticated administrator account creation.
PoC: WP-CVE-2025-6934
WP-CVE-2025-6934 | Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
PoC: CVE-2025-6934
CVE-2025-6934 - Exploit WordPress Opal Estate Pro
PoC: CVE-2025-6934
exploit
PoC: CVE-2025-6934
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
PoC: CVE-2025-6934
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free