{"id":"CVE-2025-6254","title":"The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8","summary":"The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can regi…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"published":"2026-06-10","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:10:00.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-6254","references":[{"url":"https://themeforest.net/item/doctreat-doctors-directory-wordpress-theme/24867777","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fa37909-932c-4879-bbf0-8b44cc995cc0?source=cve","label":"security@wordfence.com"}],"tags":["nvd","exploit-available"],"epss":0.00494,"epssPercentile":0.40125,"exploits":{"github":2,"githubRepos":["https://github.com/xxconi/CVE-2025-6254","https://github.com/Yucaerin/CVE-2025-6254"],"checkedAt":"2026-10-01T16:12:54.749Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T21:25:07.738Z","slug":"CVE-2025-6254","body":"## Overview\n\nThe Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}