CVE-2025-6934 Scanner

Targets the user registration endpoint via missing role restrictions, allowing attackers to create admin accounts without authentication.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 3 weeks

Scan only one

Domain, Subdomain, IPv4

Toolbox

The Opal Estate Pro plugin is a property management tool used by WordPress sites to efficiently handle real estate listings. Developed by Themeforest, it offers users the ability to manage properties directly from WordPress. The plugin is popular among real estate agencies looking to showcase property listings online. Its features include advanced listing options, property searches, and membership functionality. Users prefer it for its seamless integration with WordPress and ease of use.

CVE-2025-6934 is an unauthenticated privilege escalation vulnerability that arises from missing role restrictions in the user registration process. The plugin fails to properly validate user roles during registration, allowing attackers to specify an administrator role without any authentication. This flaw stems from inadequate authorization checks in the registration handler.

Specifically, the vulnerability exists in the user registration function that processes the `opalestate-register-nonce` parameter. Attackers can craft a registration request with a role parameter set to 'administrator', bypassing the intended role assignment logic. The endpoint does not verify the user's current privileges or enforce role restrictions, enabling unauthenticated admin account creation.

If exploited, an attacker can gain full administrative control over the WordPress site, including the ability to modify content, install plugins, and access sensitive data. This can lead to complete site compromise, data breaches, and potential use of the site for malicious activities. The high CVSS score of 9.8 reflects the critical nature of this vulnerability.

Get started to protecting your digital assets