CVE-2025-4519 HIGH

CVE-2025-4519: IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function

Vendor Themeatelier
Product IDonate – Blood Donation, Request And Donor Management System
Weakness CWE-285
Published November 7, 2025
Last update November 7, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate a password reset for any user (including administrators) and elevate their privileges for full site takeover.

Explanation of Vulnerability in Simple Terms

02Summary

IDonate versions 2.1.5 through 2.1.9 contain an improper access control vulnerability that allows authenticated users with low privileges to read, modify, or delete sensitive data and disrupt site operations. The vulnerability requires a valid user account but no additional user interaction. An attacker can escalate their capabilities beyond their intended role permissions.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete sensitive data; disrupt site availability with a valid low-privilege user account.

Potential impact on your site

04Site Impact

Unauthorized data access, modification, or deletion; potential service disruption affecting blood donation management.

Conditions required to exploit

05Prerequisites

Attacker must have a valid user account with low privileges; no user interaction required.

Key dates

06Disclosure timeline

November 7, 2025 CVE published
November 7, 2025 Record updated

Related vulnerabilities

08Related CVE