CyberRota
← Ana sayfaya dön

CVE-2025-6254

CRITICAL · CVSS 9.8 EPSS %0.49

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-10T10:16:29.827 · Çekilme zamanı: 2026-06-30T18:18:04.024170+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2025-6254
Severity
CRITICAL
CVSS
9.8
EPSS
%0.49
WordPress

Orijinal NVD Açıklaması

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.