WPDeeply
Download free plugin
Plugin Security

Doctreat

Two critical unauthenticated flaws affect Doctreat through version 1.7.0: arbitrary file upload in the theme and privilege escalation in Doctreat Core.

Doctreat WordPress theme affected by CVE-2026-39770 and CVE-2026-39773

Two critical vulnerabilities affect the Doctreat medical-directory WordPress package: an unauthenticated arbitrary file upload in the Doctreat theme and an unauthenticated privilege-escalation flaw in the bundled Doctreat Core plugin. Both advisories cover versions up to and including 1.7.0.

Component Vulnerability CVE Affected versions Severity
Doctreat theme Unauthenticated arbitrary file upload CVE-2026-39770 <= 1.7.0 Critical, CNA CVSS 10.0
Doctreat Core Unauthenticated privilege escalation CVE-2026-39773 <= 1.7.0 Critical, CNA CVSS 10.0

Why this combination is dangerous

Neither issue requires an attacker account or victim interaction. CVE-2026-39770 can allow a remote visitor to place a dangerous file on the server when file-type validation is bypassed. If the uploaded file is reachable and executable by PHP, the result can be remote code execution and complete site compromise.

CVE-2026-39773 is an incorrect-privilege-assignment flaw in Doctreat Core. The public advisory does not disclose the affected handler or role-changing parameter, but the published vector requires no privileges and reports high confidentiality, integrity, and availability impact. A successful attack could create or elevate an account beyond its intended role.

Together, the flaws threaten both common takeover paths: direct server-side code execution and unauthorized administrative access.

Patch status

The public CVE and vulnerability-database records identify versions through 1.7.0 as affected. AmentoTech’s ThemeForest changelog lists Doctreat 1.7.1, released August 5, 2026, which is outside the published affected range. However, the public advisories do not explicitly identify a confirmed safe Doctreat Core version.

Recommended action: obtain the newest complete Doctreat package from the vendor, update both the theme and every bundled Doctreat plugin, and verify that neither component remains at 1.7.0 or earlier. If the installed Doctreat Core build is still 1.7.0, or the vendor cannot confirm a fixed build, deactivate it and switch away from the affected theme until a verified patch is available.

Immediate remediation

  1. Back up the database and files before changing the active theme.
  2. Update the full Doctreat package from the authorized vendor source. Do not update only the parent theme while leaving an older bundled Core plugin active.
  3. Confirm the installed theme and plugin versions with WP-CLI.
  4. If no fixed Doctreat Core build is available, deactivate the plugin and replace the theme temporarily.
  5. Rotate all administrator passwords and WordPress salts if compromise is suspected.
  6. Review administrator accounts and recently written executable files before returning the site to service.
wp theme list --fields=name,status,version
wp plugin list --fields=name,status,version
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Indicators of compromise

The public advisories do not publish a request path, payload, or attacker infrastructure. Defenders should therefore look for behavior rather than a single signature:

  • New administrator accounts that were not created through an approved workflow.
  • Unexpected role changes or password-reset events.
  • PHP, PHTML, PHAR, CGI, or similarly executable files created under wp-content/uploads or writable Doctreat directories.
  • Recently modified theme or plugin PHP files that do not match the vendor package.
  • POST requests to Doctreat registration, profile, avatar, document, prescription, or media-upload handlers followed by requests to a newly created file.
find wp-content/uploads -type f \( -iname "*.php" -o -iname "*.phtml" -o -iname "*.phar" -o -iname "*.cgi" \) -print
find wp-content/themes/doctreat wp-content/plugins -type f -mtime -7 -print
wp core verify-checksums
wp plugin verify-checksums --all

Note: premium components may not have WordPress.org checksums. Compare those files with a freshly downloaded vendor package instead of treating a missing checksum as proof of compromise.

Temporary hardening when removal is delayed

Disabling PHP execution in the uploads directory can reduce the impact of an arbitrary upload. This is a compensating control, not a patch, and it does not address privilege escalation in Doctreat Core.

Apache

<FilesMatch "\.(php|phtml|phar|php[0-9]?)$">
    Require all denied
</FilesMatch>

Nginx

location ~* ^/wp-content/uploads/.*\.(?:php|phtml|phar|php[0-9]?)$ {
    deny all;
    return 403;
}

Also disable public registration if it is not required, restrict administrative access with multi-factor authentication, and monitor user-role changes. These measures do not make an affected Doctreat installation safe; removal or a verified vendor patch remains the correct response.

Verification after remediation

  • The active Doctreat theme is newer than 1.7.0, or a different theme is active.
  • Doctreat Core is newer than 1.7.0 and explicitly confirmed fixed by the vendor, or it is inactive.
  • No unknown administrator accounts remain.
  • No executable files are present in uploads or other user-writable directories.
  • Access logs show no follow-up requests to suspicious newly created files.

Exploitation status

As of October 10, 2026, neither CVE appears in CISA’s Known Exploited Vulnerabilities catalog, and the reviewed authoritative records do not confirm active exploitation. That absence should not be treated as safety: both flaws are network-reachable, unauthenticated, and rated critical.

Sources

Disclosure attribution: The vulnerabilities were credited to Jamaal Ahmed through the Patchstack Bug Bounty Program. WPDeeply did not discover these issues.

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.