CVE-2025-6934 affects the Opal Estate Pro – Property Management and Submission plugin for WordPress, as used by the FullHouse - Real Estate Responsive WordPress Theme, in all versions up to and including 1.7.5. The vulnerability is caused by missing role restriction logic in the plugin's 'on_regiser_user' function during user registration. Because the registration workflow does not properly constrain which role may be assigned to a newly created account, an unauthenticated attacker can supply an arbitrary role value at registration time, including highly privileged roles such as Administrator.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
Repository contains a small exploit toolkit for CVE-2025-6934 targeting the WordPress Opal Estate Pro plugin. There are 6 files total: two Python implementations (CLI and PyQt6 GUI), one Nuclei template, a README, requirements file, and license. Because the repository includes a Nuclei template, it can be considered framework-related; however, the repository also includes standalone Python exploit code. Main capability: the exploit performs unauthenticated administrator account creation by first requesting the target site root page, parsing the HTML for an `input` named `opalestate-register-nonce`, then sending a POST request to `/wp-admin/admin-ajax.php` with `action=opalestate_register_form` and `role=administrator`. If the server returns JSON with `status: true`, the tool reports successful creation of a new admin account using attacker-supplied credentials. Python CLI (`CVE-2025-6934.py`): primary standalone exploit. It accepts target URL, email, password, and optional username. It includes a `check_version` helper that requests `/wp-content/plugins/opal-estate-pro/readme.txt` and parses `Stable tag:` to estimate whether the plugin version is <= 1.7.5, though this function is not invoked from `main()`. The actual exploit path is `get_nonce()` followed by `exploit()`. Output is colorized with colorama. Python GUI (`CVE-2025-6934-GUI.py`): same exploit logic wrapped in a PyQt6 interface. It validates user input, runs exploitation in a background `QThread`, logs progress, fetches the nonce from the base URL, and posts the same registration payload to `/wp-admin/admin-ajax.php`. Nuclei template (`CVE-2025-6934.yaml`): intrusive two-step HTTP workflow. Step 1 requests `/` and checks for `opalestate-register-nonce`, extracting the nonce via regex. Step 2 posts to `/wp-admin/admin-ajax.php` with randomized username/password/email and `role=administrator`, then matches on `status\":true` and HTTP 200. This template is not just detection; it attempts exploitation by creating an admin account. Overall purpose: provide both operator-friendly exploitation (CLI/GUI) and scanner/framework automation (Nuclei) for exploiting a claimed privilege-escalation flaw in Opal Estate Pro <= 1.7.5. The exploit is network-based, remote, and unauthenticated, with the end result of full WordPress administrative access if successful.
This repository is a small, focused exploit repo for CVE-2025-6934 affecting the WordPress Opal Estate Pro plugin up to version 1.7.5. It contains two functional artifacts: a standalone Python exploit script and a Nuclei template. The Python script is the primary exploit implementation. It first requests /wp-content/plugins/opal-estate-pro/readme.txt to identify the plugin version, then fetches the target base page to parse an HTML input named 'opalestate-register-nonce', and finally submits a POST request to /wp-admin/admin-ajax.php with action=opalestate_register_form and role=administrator. If successful, it creates a new administrator account with a fixed username (0xTerrorAdmin) and attacker-supplied email/password. This is a true exploit, not just a detector, because it performs the full privilege-escalation/account-creation workflow. The included YAML file is a Nuclei template that reproduces the same attack path in two HTTP requests: extract the nonce from GET / and then POST the crafted registration request to the WordPress AJAX endpoint, matching on a successful JSON response. Repository structure is minimal: exploit script, Nuclei template, README, and license. Overall purpose: automate unauthenticated administrator account creation on vulnerable WordPress sites running Opal Estate Pro.
Repository contains a standalone Python exploit (exploit.py) for CVE-2025-6934 targeting the Opal Estate Pro WordPress plugin (<= 1.7.5). Structure: LICENSE, README.md (usage/impact/mitigation), requirements.txt (requests, beautifulsoup4, urllib3, colorama), and exploit.py (main code). Exploit flow (exploit.py): 1) Normalizes target URL and attempts to fingerprint plugin version by requesting `/wp-content/plugins/opal-estate-pro/readme.txt` and parsing `Stable tag:`. 2) Requests `/wp-login.php?action=register` and uses BeautifulSoup to extract the hidden/input nonce named `opalestate-register-nonce`. 3) If version check indicates <= 1.7.5 and a nonce is found, it POSTs to `/wp-admin/admin-ajax.php` with form fields including `role=administrator`, `confirmed_register=on`, `ajax=1`, and `action=opalestate_register_form` to create a new admin user. 4) On JSON success response (`{"status": true}`), it prints `[VULN]` and appends the created credentials to `save.txt`. Otherwise it prints a not-vulnerable reason (attempting to clean HTML from the server message). Capabilities: unauthenticated remote privilege escalation (admin account creation). It supports single-target mode and mass-target mode (reads URLs from a user-provided file). No post-exploitation RCE payload is included, but admin creation can enable follow-on actions (e.g., plugin upload) outside this tool.
Repository contains a single Python script (`CVE-2025-6934.py`) implementing an unauthenticated network exploit against a WordPress site believed vulnerable to CVE-2025-6934 in the “Opal Estate Pro” plugin/OpalEstate registration flow. Core flow: 1) `fetch_nonce()` performs an HTTP GET to the target base URL and parses the HTML with BeautifulSoup to locate an `<input name="opalestate-register-nonce">` value (anti-CSRF token used by the plugin’s registration form). 2) `run()` sends an HTTP POST to `<base_url>/wp-admin/admin-ajax.php` with `action=opalestate_register_form` and registration fields, explicitly setting `role=administrator`. If the server returns JSON with `status: true`, it reports success and prints the login URL and the hardcoded credentials. Exploit capability: creates a new WordPress administrator account (privilege escalation / auth bypass via insecure role assignment during registration). It is not a scanner-only script; it actively attempts account creation. The script disables TLS verification (`verify=False`) and uses fixed username/password while taking the target URL and email from CLI arguments.
Repository contains a single Python exploit script plus a README. The README claims a “Mass scan and Exploit + Auto Create Administrator Role” for CVE-2025-6934 affecting “Opal Estate Pro” and provides usage patterns for single target and bulk lists (threads, output file, verbose), noting that email/username/password are configurable. The main code (mass-regist.py) implements a threaded, network-based exploit tool using requests with SSL verification disabled, retry/backoff, and User-Agent rotation. It includes WordPress fingerprinting logic (e.g., checking for wp-content and probing /readme.html for version) and then attempts exploitation per target via HTTP requests (details of the exact exploit request flow are partially truncated in the provided content, but the script’s stated purpose and output handling indicate unauthenticated creation of an Administrator account). It tracks successful targets, writes credentials and target info to an output file, logs to exploit.log, and generates final_report.json summarizing totals and success rate.
Repository contains a Python PoC exploit for CVE-2025-6934 affecting the WordPress plugin Opal Estate Pro <= 1.7.5. The core capability is unauthenticated administrator account creation by abusing a vulnerable WordPress AJAX handler. Structure: - CVE-2025-6934.py: Single-target exploit. It (1) fetches the target homepage and extracts the registration nonce named 'opalestate-register-nonce' (via BeautifulSoup, with regex fallback), then (2) POSTs to /wp-admin/admin-ajax.php with action=opalestate_register_form and role=administrator to create a new admin user. It parses the response for JSON (regex '{.*}') and prints the generated credentials and the login URL (/wp-login.php). - MASS-CVE-2025-6934.py: Mass exploitation/scanning variant. Reads targets from a file, uses a ThreadPoolExecutor (default 10 threads), extracts the nonce via regex, submits the same admin-creation POST to /wp-admin/admin-ajax.php, and writes successful results (target + credentials) to results_success.txt. - README.md: States the vulnerability and affected plugin/version. Notable behaviors/assumptions: - Network-based exploitation over HTTP(S); SSL verification is disabled. - Success detection is simplistic in the mass script (checks for '"status":true' in response text). - No post-exploitation beyond account creation; payload is the crafted registration request that sets role=administrator.
This repository contains a Python 2 exploit script (CVE-2025-6934.py) and a README.md. The exploit targets the Opal Estate Pro WordPress plugin (<=1.7.5), leveraging an unauthenticated privilege escalation vulnerability (CVE-2025-6934). The script automates the process of registering a new user with administrator privileges by first extracting a required nonce from the target site, then sending a crafted POST request to the 'wp-admin/admin-ajax.php' endpoint. The script supports batch exploitation by reading a list of target URLs from a file and saves successful results to 'vulns.txt'. The README provides usage instructions and context. The exploit is operational, providing a working attack that results in full administrative access to vulnerable WordPress sites.
This repository is a proof-of-concept exploit for CVE-2025-6934, targeting the WordPress plugin Opal Estate Pro version 1.7.5 and below. The exploit demonstrates unauthenticated creation of an administrator account on a vulnerable WordPress instance. The main code is in 'main.py', which loads a key from '.key', decrypts 'main.bin' (which contains the actual exploit logic), and executes it. The exploit is written in Python and requires the 'requests', 'beautifulsoup4', and 'colorama' libraries. Usage is via command line, specifying the target URL and credentials for the new admin account. The README provides detailed instructions and example usage. The exploit is operational, as it automates the attack and provides clear output on success or failure. No hardcoded endpoints are present in the code, but the user must supply the target URL. The repository is structured with a small Python loader, an encrypted payload, and supporting documentation.
This repository provides a Proof-of-Concept (PoC) exploit for CVE-2025-6934, a critical unauthenticated privilege escalation vulnerability in the WordPress Opal Estate Pro plugin (versions <= 1.7.5). The main exploit script (CVE-2025-6934.py) is a Python tool that automates the exploitation process: it checks the plugin version, extracts a registration nonce from the target site, and submits a crafted POST request to the /wp-admin/admin-ajax.php endpoint to create a new administrator account. The exploit does not require authentication and leverages a missing role restriction in the plugin's registration handler. The repository also includes a Nuclei YAML template (CVE-2025-6934.yaml) for automated vulnerability scanning, a README with usage instructions, and a requirements.txt for dependencies. The exploit is effective against any WordPress site with the vulnerable plugin enabled and registration open, and results in full administrative compromise of the site.
This repository provides a Proof of Concept (PoC) exploit for CVE-2025-6934, a critical privilege escalation vulnerability in the WordPress Opal Estate Pro plugin (versions <= 1.7.5). The vulnerability allows unauthenticated attackers to create new administrator accounts by exploiting insufficient role restrictions in the plugin's registration process. The main exploit script (CVE-2025-6934.py) is a Python tool that: - Checks the target site for the vulnerable plugin version by fetching /wp-content/plugins/opal-estate-pro/readme.txt. - Extracts a required registration nonce from the site's front page. - Submits a crafted POST request to /wp-admin/admin-ajax.php, registering a new user with the administrator role. - Reports success or failure and displays the credentials of the newly created admin account if successful. The repository also includes a Nuclei YAML template (CVE-2025-6934.yaml) for automated vulnerability scanning, a README with usage instructions, and a requirements.txt listing Python dependencies. The exploit is network-based, requires no authentication, and targets WordPress sites with the vulnerable plugin installed. No fake or destructive code is present; the exploit is a legitimate PoC for research and security testing.
This repository contains a Python exploit script (CVE-2025-6934.py) targeting a privilege escalation vulnerability in the Opal Estate Pro WordPress plugin (versions <= 1.7.5). The exploit automates the process of checking the plugin version, retrieving a required nonce from the registration page, and sending a specially crafted POST request to the /wp-admin/admin-ajax.php endpoint. This request registers a new user with administrator privileges using attacker-supplied credentials. The script requires the target URL, email, and password as arguments. The repository also includes a README.md with usage instructions and a requirements.txt listing dependencies (requests, beautifulsoup4). The main attack vector is network-based, exploiting an unauthenticated registration process. No hardcoded IPs or domains are present; endpoints are relative to the user-supplied target URL. The exploit is operational, providing a working method to gain admin access on vulnerable WordPress installations.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.