Doctreat
Two critical unauthenticated flaws affect Doctreat through version 1.7.0: arbitrary file upload in the theme and privilege escalation in Doctreat Core.
Two critical vulnerabilities affect the Doctreat medical-directory WordPress package: an unauthenticated arbitrary file upload in the Doctreat theme and an unauthenticated privilege-escalation flaw in the bundled Doctreat Core plugin. Both advisories cover versions up to and including 1.7.0.
| Component | Vulnerability | CVE | Affected versions | Severity |
|---|---|---|---|---|
| Doctreat theme | Unauthenticated arbitrary file upload | CVE-2026-39770 | <= 1.7.0 | Critical, CNA CVSS 10.0 |
| Doctreat Core | Unauthenticated privilege escalation | CVE-2026-39773 | <= 1.7.0 | Critical, CNA CVSS 10.0 |
Why this combination is dangerous
Neither issue requires an attacker account or victim interaction. CVE-2026-39770 can allow a remote visitor to place a dangerous file on the server when file-type validation is bypassed. If the uploaded file is reachable and executable by PHP, the result can be remote code execution and complete site compromise.
CVE-2026-39773 is an incorrect-privilege-assignment flaw in Doctreat Core. The public advisory does not disclose the affected handler or role-changing parameter, but the published vector requires no privileges and reports high confidentiality, integrity, and availability impact. A successful attack could create or elevate an account beyond its intended role.
Together, the flaws threaten both common takeover paths: direct server-side code execution and unauthorized administrative access.
Patch status
The public CVE and vulnerability-database records identify versions through 1.7.0 as affected. AmentoTech’s ThemeForest changelog lists Doctreat 1.7.1, released August 5, 2026, which is outside the published affected range. However, the public advisories do not explicitly identify a confirmed safe Doctreat Core version.
Recommended action: obtain the newest complete Doctreat package from the vendor, update both the theme and every bundled Doctreat plugin, and verify that neither component remains at 1.7.0 or earlier. If the installed Doctreat Core build is still 1.7.0, or the vendor cannot confirm a fixed build, deactivate it and switch away from the affected theme until a verified patch is available.
Immediate remediation
- Back up the database and files before changing the active theme.
- Update the full Doctreat package from the authorized vendor source. Do not update only the parent theme while leaving an older bundled Core plugin active.
- Confirm the installed theme and plugin versions with WP-CLI.
- If no fixed Doctreat Core build is available, deactivate the plugin and replace the theme temporarily.
- Rotate all administrator passwords and WordPress salts if compromise is suspected.
- Review administrator accounts and recently written executable files before returning the site to service.
wp theme list --fields=name,status,version
wp plugin list --fields=name,status,version
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
Indicators of compromise
The public advisories do not publish a request path, payload, or attacker infrastructure. Defenders should therefore look for behavior rather than a single signature:
- New administrator accounts that were not created through an approved workflow.
- Unexpected role changes or password-reset events.
- PHP, PHTML, PHAR, CGI, or similarly executable files created under
wp-content/uploadsor writable Doctreat directories. - Recently modified theme or plugin PHP files that do not match the vendor package.
- POST requests to Doctreat registration, profile, avatar, document, prescription, or media-upload handlers followed by requests to a newly created file.
find wp-content/uploads -type f \( -iname "*.php" -o -iname "*.phtml" -o -iname "*.phar" -o -iname "*.cgi" \) -print
find wp-content/themes/doctreat wp-content/plugins -type f -mtime -7 -print
wp core verify-checksums
wp plugin verify-checksums --all
Note: premium components may not have WordPress.org checksums. Compare those files with a freshly downloaded vendor package instead of treating a missing checksum as proof of compromise.
Temporary hardening when removal is delayed
Disabling PHP execution in the uploads directory can reduce the impact of an arbitrary upload. This is a compensating control, not a patch, and it does not address privilege escalation in Doctreat Core.
Apache
<FilesMatch "\.(php|phtml|phar|php[0-9]?)$">
Require all denied
</FilesMatch>
Nginx
location ~* ^/wp-content/uploads/.*\.(?:php|phtml|phar|php[0-9]?)$ {
deny all;
return 403;
}
Also disable public registration if it is not required, restrict administrative access with multi-factor authentication, and monitor user-role changes. These measures do not make an affected Doctreat installation safe; removal or a verified vendor patch remains the correct response.
Verification after remediation
- The active Doctreat theme is newer than 1.7.0, or a different theme is active.
- Doctreat Core is newer than 1.7.0 and explicitly confirmed fixed by the vendor, or it is inactive.
- No unknown administrator accounts remain.
- No executable files are present in uploads or other user-writable directories.
- Access logs show no follow-up requests to suspicious newly created files.
Exploitation status
As of October 10, 2026, neither CVE appears in CISA’s Known Exploited Vulnerabilities catalog, and the reviewed authoritative records do not confirm active exploitation. That absence should not be treated as safety: both flaws are network-reachable, unauthenticated, and rated critical.
Sources
- Wordfence Intelligence: Doctreat theme arbitrary file upload
- Patchstack: CVE-2026-39770
- Patchstack: CVE-2026-39773
- NVD: CVE-2026-39770
- NVD: CVE-2026-39773
- AmentoTech vendor changelog
Disclosure attribution: The vulnerabilities were credited to Jamaal Ahmed through the Patchstack Bug Bounty Program. WPDeeply did not discover these issues.