plugin

Wp Whydonate Vulnerabilities

3 known security issues reported for the Wp Whydonate WordPress plugin. Most recent disclosed Oct 20, 2025.

3 medium

Running Wp Whydonate on your site? Check whether your installed version is affected.

Scan your site free

Whydonate <= 4.0.15 - Missing Authorization

medium

The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.15. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.0.15
Fixed in:
4.0.16
Disclosed:
Oct 20, 2025

CVE-2025-49899 on NVD →

WhyDonate – FREE Donate button – Crowdfunding – Fundraising <= 4.0.15 - Missing Authorization to Unauthenticated wp_wdplugin_style Rww Deletion

medium

The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the remove_row function in all versions up to, and including, 4.0.15. This makes it possible for unauthenticated attackers to delete rows from the wp_wdplu...

CVSS:
5.3
Affected:
up to 4.0.15
Fixed in:
4.0.16
Disclosed:
Oct 14, 2025

CVE-2025-10186 on NVD →

Whydonate – FREE Donate button <= 3.12.14 - Cross-Site Request Forgery

medium

The Whydonate – FREE Donate button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.14. This is due to missing nonce validation on several functions. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted t...

CVSS:
4.3
Affected:
up to 3.12.14
Fixed in:
3.12.16
Disclosed:
May 10, 2023

CVE-2023-29238 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database