Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 02 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Jul 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering. | |
| Title | Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user' | |
| Weaknesses | CWE-269 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-07-02T13:24:45.496Z
Reserved: 2025-06-30T17:52:44.462Z
Link: CVE-2025-6934
Updated: 2025-07-01T13:47:17.937Z
Status : Awaiting Analysis
Published: 2025-07-01T07:15:27.340
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-6934
No data.
OpenCVE Enrichment
Updated: 2025-07-13T22:31:33Z