info: name: The Opal Estate Pro – Property Management <= 1.7.5 - Unauthenticated Privilege Escalation author: pussycat0x severity: critical description: | The Opal Estate Pro plugin (≤ 1.7.5) is vulnerable to privilege escalation.Due to missing role restrictions in the on_regiser_user function, users can register with any role. This allows unauthenticated attackers to create administrator accounts reference: - https://github.com/Nxploited/CVE-2025-6934/blob/main/README.md metadata: verified: true tags: cve,cve2025,wordpress,intrusive,plugin,opalestate