Executive brief
The Doctreat Core plugin for WordPress, which provides directory and booking functionality for medical professionals, contains a critical security flaw. This vulnerability allows any person on the internet to register a new account with full administrative privileges. An attacker could use this access to take complete control of the website, steal sensitive patient or customer data, and disrupt medical directory services.
Technical details
The Doctreat Core plugin for WordPress is vulnerable to privilege escalation due to a lack of role validation in the doctreat_process_registration() function. This function fails to restrict the user roles that can be assigned during the registration process. An unauthenticated remote attacker can exploit this by submitting a registration request that specifies a high-privileged role, such as 'administrator'. This allows for complete site takeover. The vulnerability affects all versions of the plugin up to and including 1.6.8.
Affected products
- Doctreat Doctreat Core Up to and including 1.6.8
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory: NVD and Wordfence published the advisory.