Critical severity9.8NVD Advisory· Published Jun 10, 2026
CVE-2025-6254
CVE-2025-6254
Description
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.
Affected products
2<=1.6.8+ 1 more
- (no CPE)range: <=1.6.8
- (no CPE)range: <=1.6.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.