CVE-2025-11154: Themeatelier Idonate

Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

Affected products

Published 2025-10-27. Last modified 2026-10-08.