The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary user_id parameter value to the wp_delete_user() function, authenticated attackers, with Subscriber-level access and above could delete arbitrary user accounts, including those of administrators.
History

Fri, 07 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeatelier
Themeatelier idonate
Wordpress
Wordpress wordpress
Vendors & Products Themeatelier
Themeatelier idonate
Wordpress
Wordpress wordpress

Fri, 07 Nov 2025 04:45:00 +0000

Type Values Removed Values Added
Description The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary user_id parameter value to the wp_delete_user() function, authenticated attackers, with Subscriber-level access and above could delete arbitrary user accounts, including those of administrators.
Title IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-11-07T04:28:54.987Z

Updated: 2025-11-07T14:55:14.133Z

Reserved: 2025-05-09T21:42:43.790Z

Link: CVE-2025-4522

cve-icon Vulnrichment

Updated: 2025-11-07T14:55:08.345Z

cve-icon NVD

Status : Received

Published: 2025-11-07T05:16:04.443

Modified: 2025-11-07T05:16:04.443

Link: CVE-2025-4522

cve-icon Redhat

No data.