Arbitrary File Upload Vulnerability in Doccure Theme for WordPress
CVE-2025-9112
8.8HIGH
What is CVE-2025-9112?
The Doccure theme for WordPress possesses a vulnerability stemming from improper file type validation within the 'doccure_temp_file_uploader' function. This flaw affects all versions up to and including 1.4.8, allowing authenticated users with subscriber-level permissions and higher to upload arbitrary files to the server. If exploited, this vulnerability can lead to potential remote code execution, posing significant security risks to the affected websites.
Affected Version(s)
Doccure * <= 1.4.8