info: name: The Opal Estate Pro – Property Management <=1.7.5- Unauthenticated Privilege Escalation author: pussycat0x severity: critical description: | The Opal Estate Pro plugin (≤ 1.7.5) is vulnerable to privilege escalation. Due to missing role restrictions in the on_register_user function, users can register with any role. This allows unauthenticated attackers to create administrator accounts. reference: - https://github.com/Nxploited/CVE-2025-6934/blob/main/README.md classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score:9.8 cve-id: CVE-2025-6934 cwe-id: CWE-269 impact: | An attacker can exploit this vulnerability to register with administrator privileges, gaining complete control over the WordPress site. remediation: | Update the Opal Estate Pro plugin to a version newer than 1.7.5 when available, or remove the plugin if not essential. metadata: verified:true max-request:2 vendor: themeforest product: opal-estate-pro shodan-query: http.component:"wordpress"&& http.html:"/wp-content/plugins/opal-estate-pro/" tags: cve,cve2025,wordpress,wp-plugin,wp,intrusive,plugin,opalestate