CVE-2025-11154
27.10.2025, 06:15
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
| Vendor | Product | Version |
|---|---|---|
| themeatelier | idonate | 𝑥 < 2.1.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration