Sceawere
Vulnerability Detail
CVE-2026-39773UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Doctreat Core Unauthenticated Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 16h ago
- Vendor
- AmentoTech
- Product
- Doctreat Core
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-06T09:17:49.900Z",
"pubdate": "2026-10-06T09:17:49.900Z",
"executiveSummary": "The Doctreat Core plugin for WordPress, in versions up to and including 1.7.0, contains a critical vulnerability allowing for unauthenticated privilege escalation.\nThis vulnerability stems from improper validation of user-controlled input during account creation or profile update processes, enabling unauthorized actors to modify their user roles.\nAn unauthenticated attacker can exploit this flaw to elevate their privileges to that of an administrator, gaining full control over the affected WordPress instance.\nThe risk implication is severe, as successful exploitation facilitates complete site compromise, including arbitrary code execution, sensitive data theft, and site defacement.\nThe exploit does not require prior authentication, making it particularly dangerous as it targets the public-facing registration or profile management functionality of the plugin.\nSystem administrators are strongly advised to restrict access to registration endpoints or implement robust role validation measures until a patch is applied.",
"technicalDetails": "The vulnerability resides within the core functionality of the Doctreat Core plugin, specifically in how it processes user-provided parameters during the registration or profile update lifecycle.\nThe root cause is a failure to implement server-side validation or 'allow-listing' for user role assignments. When a request is processed, the plugin's backend logic accepts a role parameter directly from the HTTP request, which is then used in a function responsible for updating user meta or database records associated with the user's role.\nBecause the plugin does not verify if the authenticated (or unauthenticated) user possesses the necessary administrative authorization to change a role, it blindly assigns the requested privilege level provided in the payload.\nAn attacker can exploit this by intercepting the registration or profile update request and injecting a role parameter (e.g., 'administrator' or 'subscriber' depending on the database schema) into the request body via POST request. By appending or replacing the user role parameter in the request, the application updates the underlying wp_users or corresponding user metadata table with the elevated privilege level.\nThe attack flow proceeds as follows: First, the attacker identifies the endpoint responsible for user registration or profile management within the Doctreat Core plugin. Second, the attacker crafts a malicious HTTP request, ensuring the inclusion of the role modification parameter. Third, the request is transmitted to the server without the need for a valid session token or authentication cookie. Finally, the server-side processing logic consumes the input, fails to enforce role-based access control (RBAC), and updates the user's privilege status in the database.\nThe affected versions are <= 1.7.0. The vulnerability is network-exposed, as it relies on standard HTTP traffic directed at the web server. The post-exploitation impact is catastrophic, as elevating privileges to administrator grants the attacker access to all administrative panels, theme editors, and plugin management consoles, effectively bypassing the security model of the WordPress site."
}