Feed/CVE-2025-6934
CVE-2025-6934CRITICALCVSS 9.8

CVE-2025-6934

Published Jul 1, 2025·Updated Jun 17, 2026

NVD Description

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.

Public Exploits & PoCs8 found

PoC: CVE-2025-6934

CVE-2025-6934 POC

1

PoC: CVE-2025-6934-PoC

CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro

PoC: CVE-2025-6934

This repository contains a Proof of Concept (PoC) exploit for CVE-2025-6934, a critical vulnerability in WordPress Plugin: Opal Estate Pro <= 1.7.5, allowing unauthenticated administrator account creation.

PoC: WP-CVE-2025-6934

WP-CVE-2025-6934 | Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation

PoC: CVE-2025-6934

CVE-2025-6934 - Exploit WordPress Opal Estate Pro

PoC: CVE-2025-6934

exploit

PoC: CVE-2025-6934

CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.

PoC: CVE-2025-6934

Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free