Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
criticalThe Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an a...
- CVSS:
- 9.8
- Affected:
- up to 1.6.8
- Fixed in:
- 1.7.0
- Disclosed:
- Jun 9, 2026