CVE-2025-11154: Themeatelier Idonate
Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
Affected products
- Themeatelier Idonate: before 2.1.13 (fixed in 2.1.13)
Published 2025-10-27. Last modified 2026-10-08.