Skip to main content

Threat intelligence

Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation

CVE-2025-6254 · doctreat_core

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Doctreat_core at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
Affected software
doctreat_core(Plugin)
Affected versions
  • ≤ 1.6.8
Authentication
Unauthenticated
Vulnerability type
Privilege escalation
Published
9 June 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
May allow a lower-privilege user to perform actions reserved for administrators.
Source

Data imported from Wordfence Intelligence (advisory 5fa37909-932c-4879-bbf0-8b44cc995cc0). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Doctreat_core version against this catalog when the Defence plugin is connected to your WordPress site.