CVE 5.4 MEDIUM

IDonate < 2.1.13 - Unauthenticated User Deletion_CVE-2025-11154

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

Basic Information

ID CVE-2025-11154
Source WPScan
Published Oct 27, 2025 at 06:00
Modified Oct 27, 2025 at 15:11

Affected Product

Vendor Unknown
Product IDonate
Affected Versions Unknown IDonate 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.