PT-2025-44766 · WordPress · Doccure Core Plugin

Alyudin Nafiie

·

Published

2025-11-03

·

Updated

2025-11-08

·

CVE-2025-8900

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Doccure Core plugin for WordPress versions prior to 1.5.4
Description The Doccure Core plugin for WordPress allows privilege escalation in versions prior to 1.5.4. This occurs because the plugin permits users creating new accounts to define their own role, specifically through the user type field. This enables unauthenticated attackers to obtain elevated privileges by registering an account with administrator rights.
Recommendations Update the Doccure Core plugin to version 1.5.4 or later.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-8900

Affected Products

Doccure Core Plugin