CVE-2025-6934
nicheUnauthenticated Privilege Escalation in Opal Estate Pro WordPress Plugin
The Opal Estate Pro – Property Management and Submission plugin for WordPress fails to restrict the role assigned to users during self-registration in its 'on_regiser_user' function. Because this registration path requires no authentication, an unauthenticated attacker can submit a registration request while arbitrarily specifying a role, including the Administrator role. The attacker then gains full administrator access to the affected WordPress site, allowing complete site takeover including content changes, plugin/theme installation, and further compromise. All sites running the plugin in any version up to and including 1.7.5 are affected, including sites using the FullHouse – Real Estate Responsive WordPress Theme, which bundles the plugin. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the flaw's 26.4% EPSS score (98th percentile) indicates a meaningful probability of exploitation within 30 days.
What to do: Update Opal Estate Pro to the first release after 1.7.5 (check the vendor changelog for the patched version) on all sites, including those running the FullHouse theme. As an interim mitigation, disable the plugin or restrict new user registrations until the update is applied. Audit existing user accounts for unexpected administrators created via the registration form, since attackers may have already escalated privileges silently.
| WpOpal (Opal) Opal Estate Pro – Property Management and Submission (WordPress plugin) | all versions up to and including 1.7.5 |
| WpOpal (Opal) FullHouse – Real Estate Responsive WordPress Theme (bundles the affected plugin) | all versions bundling Opal Estate Pro up to and including 1.7.5 (specific theme versions not specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.