CVE-2025-2798: Woffice <= 5.4.21 - Authentication Bypass via Registration Role
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2798?
CVE-2025-2798 is classified as a high severity vulnerability due to the potential for unauthenticated attackers to gain Administrator access.
How do I fix CVE-2025-2798?
To fix CVE-2025-2798, update the Woffice CRM theme for WordPress to version 5.4.22 or later.
Who is affected by CVE-2025-2798?
CVE-2025-2798 affects all versions of the Woffice CRM theme for WordPress up to and including 5.4.21.
What is the main issue caused by CVE-2025-2798?
CVE-2025-2798 allows unauthenticated users to register as Administrators due to misconfiguration of excluded roles.
When was CVE-2025-2798 published?
CVE-2025-2798 was published on April 1, 2025.