VYPR
Critical severity9.8NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026

CVE-2025-6254

CVE-2025-6254

Description

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

1