The Opal Estate Pro – Property Management and Submission...
Critical severity
Unreviewed
Published
Jul 1, 2025
to the GitHub Advisory Database
•
Updated Jul 1, 2025
Description
Published by the National Vulnerability Database
Jul 1, 2025
Published to the GitHub Advisory Database
Jul 1, 2025
Last updated
Jul 1, 2025
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.
References