Impact
The vulnerability stems from a misconfigured exclusion list that permits new registrations to receive an Administrator role, allowing unauthenticated users to create accounts with full administrative privileges through a custom login form. The flaw represents a classic authentication bypass (CWE‑269) that elevates privilege without legitimate approval.
Affected Systems
The issue affects the XTENDIFY Woffice CRM theme for WordPress. All releases from the earliest through 5.4.21 are vulnerable; users running any of those versions should review and upgrade.
Risk and Exploitability
The CVSS score of 9.8 signals a critical weakness. The EPSS score of 1% indicates a small but non‑negligible chance of exploitation. Although not listed in the CISA KEV catalog, the ability to create administrator accounts from the front‑end and combine with a second flaw (CVE‑2025‑2797) makes it an attractive target. Access requires an unauthenticated web request to the registration endpoint, and the attacker needs a custom login form to trigger the bypass.
OpenCVE Enrichment
EUVD