IDonatePro [idonate-pro] <= 2.1.9 (unfixed)
unknown
[en] Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonatePro: from n/a through <= 2.1.9.
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-58938 on NVD →
IDonatePro [idonate-pro] <= 2.1.11 (unfixed)
unknown
[en] Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects IDonatePro: from n/a through <= 2.1.11.
- Affected:
- up to 2.1.11
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-60045 on NVD →
IDonatePro [idonate-pro] <= 2.1.9 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeAtelier IDonatePro idonate-pro allows Retrieve Embedded Sensitive Data.This issue affects IDonatePro: from n/a through <= 2.1.9.
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-52752 on NVD →
IDonatePro <= 2.1.11 - Missing Authorization
medium
The IDonatePro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.11. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.11
- Fix:
- No patched version reported
- Disclosed:
- Aug 22, 2025
CVE-2025-60045 on NVD →
IDonatePro <= 2.1.9 - Missing Authorization
medium
The IDonatePro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Aug 21, 2025
CVE-2025-58938 on NVD →
IDonatePro <= 2.1.9 - Authenticated (Subscriber+) Information Exposure
medium
The IDonatePro - Blood Donation, Request And Donor Management WordPress Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or config...
- CVSS:
- 4.3
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Aug 17, 2025
CVE-2025-52752 on NVD →
IDonatePro [idonate-pro] < 2.1.9
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro allows PHP Local File Inclusion. This issue affects IDonatePro: from n/a through 2.1.9.
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Aug 14, 2025
CVE-2025-30635 on NVD →
IDonatePro [idonate-pro] <= 2.1.9 (unfixed)
unknown
[en] Missing Authorization vulnerability in ThemeAtelier IDonatePro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IDonatePro: from n/a through 2.1.9.
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025
CVE-2025-30639 on NVD →
IDonatePro <= 2.1.9 - Missing Authorization
medium
The IDonatePro - Blood Donation, Request And Donor Management WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.9
- Fix:
- No patched version reported
- Disclosed:
- Aug 8, 2025
CVE-2025-30639 on NVD →
IDonatePro <= 2.1.8 - Unauthenticated Local File Inclusion
high
The IDonatePro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls,...
- CVSS:
- 8.1
- Affected:
- up to 2.1.8
- Fix:
- No patched version reported
- Disclosed:
- Jul 16, 2025
CVE-2025-30635 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database