The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.4.8. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 08 Sep 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.4.8. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. | |
Title | Doccure <= 1.4.8 - Unauthenticated Arbitrary User Password Change | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-09-08T19:44:19.751Z
Reserved: 2025-08-18T09:06:53.080Z
Link: CVE-2025-9114

Updated: 2025-09-08T19:34:24.082Z

Status : Received
Published: 2025-09-08T19:15:38.007
Modified: 2025-09-08T19:15:38.007
Link: CVE-2025-9114

No data.

No data.