CVE-2025-6254
CRITICALDoctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 2 public exploits for CVE-2025-6254. PoCs published by Yucaerin, xxconi.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2025-6254, an unauthenticated privilege escalation vulnerability in Doctreat Core <= 1.6.8. The exploit automates nonce extraction and submits a crafted registration request to create an administrator account.
Description
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.
Exploits (2)
The repository contains a functional Python exploit for CVE-2025-6254, an unauthenticated privilege escalation vulnerability in Doctreat Core <= 1.6.8. The exploit automates nonce extraction and submits a crafted registration request to create an administrator account.
This repository contains a functional Python exploit for CVE-2025-6254, an unauthenticated privilege escalation vulnerability in Doctreat Core <= 1.6.8. The exploit automates the creation of an administrator account by leveraging insecure AJAX registration actions and nonce handling.
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H