VendorsThemeAtelieridonateall versions
Vulnerabilities

ThemeAtelier IDonate

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-32519
WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerability
Published 2025-04-11 · Modified
9.8EPSS 0.009
CVE-2025-4519
IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function
Published 2025-11-07 · Analyzed
8.8EPSS 0.003
CVE-2024-3594
IDonate <= 1.9.0 - Admin+ Stored XSS
Published 2024-05-23 · Analyzed
8.7EPSS 0.005
CVE-2025-4523
IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function
Published 2025-08-01 · Analyzed
6.5EPSS 0.003
CVE-2025-4522
IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function
Published 2025-11-07 · Analyzed
6.5EPSS 0.003
CVE-2025-11154
IDonate < 2.1.13 - Unauthenticated User Deletion
Published 2025-10-27 · Analyzed
5.4EPSS 0.001
CVE-2025-12877
IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
Published 2025-11-22 · Modified
5.3EPSS 0.003
CVE-2025-67583
WordPress IDonate plugin <= 2.1.15 - Broken Access Control vulnerability
Published 2025-12-09 · Modified
5.3EPSS 0.002