What the vulnerability does
01Description
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate a password reset for any user (including administrators) and elevate their privileges for full site takeover.
Explanation of Vulnerability in Simple Terms
02Summary
IDonate versions 2.1.5 through 2.1.9 contain an improper access control vulnerability that allows authenticated users with low privileges to read, modify, or delete sensitive data and disrupt site operations. The vulnerability requires a valid user account but no additional user interaction. An attacker can escalate their capabilities beyond their intended role permissions.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete sensitive data; disrupt site availability with a valid low-privilege user account.
Potential impact on your site
04Site Impact
Unauthorized data access, modification, or deletion; potential service disruption affecting blood donation management.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low privileges; no user interaction required.
Key dates
06Disclosure timeline
November 7, 2025
CVE published
November 7, 2025
Record updated