PT-2025-36493 · Dreamstechnologies · Doccure

István Márton

·

Published

2025-09-08

·

Updated

2025-09-08

·

CVE-2025-9112

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure temp file uploader' function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9112

Affected Products

Doccure