Missing Authorization Vulnerability in e-plugins Hospital Doctor Directory
CVE-2025-69186

7.3HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2026

What is CVE-2025-69186?

A missing authorization vulnerability exists in the Hospital Doctor Directory plugin, which allows attackers to exploit improperly configured access control security levels. This weakness affects versions up to and including 1.3.9, potentially enabling unauthorized users to gain access to sensitive information or functionalities within the application.

Affected Version(s)

Hospital Doctor Directory 0 <= 1.3.9

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.