5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
Basic Information
ID
CVE-2025-11154
Source
WPScan
Published
Oct 27, 2025 at 06:00
Modified
Oct 27, 2025 at 15:11
Affected Product
Vendor
Unknown
Product
IDonate
Affected Versions
Unknown IDonate 0