ZeroHour

CVE-2025-11154

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p3
Published
()
Modified
Description

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

Vendors
themeatelier
Products
idonate
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.