The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
History

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 06:15:00 +0000

Type Values Removed Values Added
Description The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
Title IDonate < 2.1.13 - Unauthenticated User Deletion
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-10-27T06:00:01.632Z

Updated: 2025-10-27T15:11:51.813Z

Reserved: 2025-09-29T13:45:16.966Z

Link: CVE-2025-11154

cve-icon Vulnrichment

Updated: 2025-10-27T15:11:44.691Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-27T06:15:37.020

Modified: 2025-10-27T16:15:35.940

Link: CVE-2025-11154

cve-icon Redhat

No data.