PT-2025-44766 · WordPress · Doccure Core Plugin

·

CVE-2025-8900

·

Published

2025-11-03

·

Updated

2025-11-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Doccure Core plugin for WordPress versions prior to 1.5.4
Description The Doccure Core plugin for WordPress allows privilege escalation in versions prior to 1.5.4. This occurs because the plugin permits users creating new accounts to define their own role, specifically through the user type field. This enables unauthenticated attackers to obtain elevated privileges by registering an account with administrator rights.
Recommendations Update the Doccure Core plugin to version 1.5.4 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8900

Affected Products

Doccure Core Plugin