CVE-2025-6758

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during user registration.
Configurations

No configuration.

History

19 Aug 2025, 13:42

Type Values Removed Values Added
Summary
  • (es) El tema Real Spaces - WordPress Properties Directory Theme para WordPress es vulnerable a la escalada de privilegios mediante la función 'imic_agent_register' en todas las versiones hasta la 3.6 incluida. Esto se debe a la falta de restricciones en el rol de registro. Esto permite que atacantes no autenticados elijan arbitrariamente su rol, incluido el de Administrador, durante el registro de usuarios.

19 Aug 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 07:15

Updated : 2025-08-19 13:42


NVD link : CVE-2025-6758

Mitre link : CVE-2025-6758

CVE.ORG link : CVE-2025-6758


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management