Description
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.4.8. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
* (semver)
Timeline
| 2025-08-18: | Discovered |
| 2025-09-08: | Disclosed |
Credits
István Márton
References
www.wordfence.com/...-b2b6-415c-91f2-e5b98048258d?source=cve
themeforest.net/.../doccure-medical-wordpress-theme/34329202