CVE-2025-10186: Jjlemstra Whydonate – Free Donate Button – Crowdfunding – Fundraising
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the remove_row function in all versions up to, and including, 4.0.15. This makes it possible for unauthenticated attackers to delete rows from the wp_wdplugin_style table.
Affected products
- Jjlemstra Whydonate – Free Donate Button – Crowdfunding – Fundraising: up to and including 4.0.15
Published 2025-10-15. Last modified 2026-10-08.