CVE-2025-6934: Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'onregiseruser' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Opal Estate Pro (Property Management and Submission) WordPress pluginto a version that resolves this vulnerability.Fixed in 1.7.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6934?
CVE-2025-6934 has a medium severity due to the potential for privilege escalation.
How do I fix CVE-2025-6934?
To fix CVE-2025-6934, update the Opal Estate Pro plugin to version 1.7.6 or later.
Which versions of Opal Estate Pro are affected by CVE-2025-6934?
CVE-2025-6934 affects all versions up to and including 1.7.5 of the Opal Estate Pro plugin.
What type of vulnerability is CVE-2025-6934?
CVE-2025-6934 is categorized as a privilege escalation vulnerability.
Who is affected by CVE-2025-6934?
Users of the Opal Estate Pro plugin for WordPress are affected by CVE-2025-6934 if they are on the vulnerable versions.