CVE-2025-6254

CRITICAL

Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-6254. PoCs published by Yucaerin, xxconi.

AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2025-6254, an unauthenticated privilege escalation vulnerability in Doctreat Core <= 1.6.8. The exploit automates nonce extraction and submits a crafted registration request to create an administrator account.

Description

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.

Exploits (2)

github WORKING POC
by Yucaerin · pythonpoc
https://github.com/Yucaerin/CVE-2025-6254

The repository contains a functional Python exploit for CVE-2025-6254, an unauthenticated privilege escalation vulnerability in Doctreat Core <= 1.6.8. The exploit automates nonce extraction and submits a crafted registration request to create an administrator account.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Doctreat Core <= 1.6.8
No auth needed
Prerequisites: Doctreat theme active · Doctreat Core plugin <= 1.6.8 · User registration enabled
devstral-2 · analyzed Jun 18, 2026 Full analysis →
github WORKING POC
by xxconi · pythonpoc
https://github.com/xxconi/CVE-2025-6254

This repository contains a functional Python exploit for CVE-2025-6254, an unauthenticated privilege escalation vulnerability in Doctreat Core <= 1.6.8. The exploit automates the creation of an administrator account by leveraging insecure AJAX registration actions and nonce handling.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Doctreat Core <= 1.6.8
No auth needed
Prerequisites: WordPress site with Doctreat Core plugin installed and vulnerable
devstral-2 · analyzed Jun 12, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 34.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
AmentoTech/Doctreat Core < 1.6.8
Published Jun 10, 2026
Tracked Since Jun 10, 2026