PT-2026-48395 · WordPress · Doctreat Core

·

CVE-2025-6254

·

Published

2026-06-10

·

Updated

2026-06-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Doctreat Core plugin for WordPress versions prior to 1.6.9
Description The plugin is subject to privilege escalation because the doctreat process registration() function does not properly restrict the roles assigned during user registration. This allows unauthenticated attackers to register an account with administrator privileges.
Recommendations Update the plugin to a version later than 1.6.8. As a temporary workaround, restrict access to the registration functionality until the update is applied.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6254

Affected Products

Doctreat Core