PT-2025-43884 · WordPress · Idonate

Khaled Alenazi

·

Published

2025-10-27

·

Updated

2025-12-05

·

CVE-2025-11154

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IDonate WordPress plugin versions prior to 2.1.13
Description The IDonate WordPress plugin is affected by a lack of authorization and Cross-Site Request Forgery (CSRF) protection when deleting users through an action handler. This allows unauthenticated attackers to delete arbitrary users.
Recommendations Update the IDonate WordPress plugin to version 2.1.13 or later.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-11154

Affected Products

Idonate