IDonate 2.0.0 – 2.1.9 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function

CVE Details

Basic Information

Title IDonate 2.0.0 – 2.1.9 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function
Type cve
Published 2025-08-01T04:24:29.620Z
Modified 2025-08-01T04:24:29.620Z

Product Information

Vendor themeatelier
Product IDonate โ€“ Blood Donation, Request And Donor Management System
Version 2.0.0

CVSS Information

Base Score 6.5 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

  • themeatelier IDonate โ€“ Blood Donation, Request And Donor Management System 2.0.0

Additional Information

CWE List CWE-200
Source Wordfence

Description

The IDonate โ€“ Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the admin_donor_profile_view() function in versions 2.0.0 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose an administratorโ€™s username, email address, and all donor fields.

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.