Impact
The Opal Estate Pro plugin’s on_regiser_user function does not enforce role validation during user registration, allowing an unauthenticated attacker to specify any role, including Administrator. This flaw enables the creation of an account with full administrative rights, compromising the confidentiality, integrity, and availability of the affected WordPress site. The vulnerability is classified as CWE‑269.
Affected Systems
WordPress installations that use the Opal Estate Pro plugin by wpopal, versions up to and including 1.7.5, are impacted. Sites that employ the FullHouse Real Estate Responsive WordPress Theme and include this plugin are also vulnerable if they run a susceptible version.
Risk and Exploitability
The CVSS score of 9.8 marks this as critical, and the EPSS score of 24% indicates a moderate to high likelihood of exploitation in the near term. Although the vulnerability is not listed in the CISA KEV catalog, it remains exploitable by anyone who can reach the registration endpoint. The likely attack vector is an unauthenticated HTTP request to the plugin’s registration handler with a manipulated role parameter to assign Administrator privileges.
OpenCVE Enrichment