CVE-2025-11154: IDonate < 2.1.13 - Unauthenticated User Deletion
Published Oct 27, 2025
·Updated
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
Affected Software
2 affected components
IDonate WordPress Plugin<2.1.13
Themeatelier Idonate Wordpress<2.1.13
Event History
Oct 27, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11154?
CVE-2025-11154 is a high severity vulnerability due to its potential for unauthenticated attacks that can lead to user deletion.
2
How do I fix CVE-2025-11154?
To fix CVE-2025-11154, update the IDonate WordPress plugin to version 2.1.13 or later.
3
What kind of attacks can exploit CVE-2025-11154?
CVE-2025-11154 can be exploited by unauthenticated attackers to delete arbitrary user accounts from a WordPress site.
4
Which versions of IDonate are affected by CVE-2025-11154?
CVE-2025-11154 affects all versions of the IDonate WordPress plugin prior to 2.1.13.
5
Does CVE-2025-11154 allow unauthorized user deletion without authentication?
Yes, CVE-2025-11154 lacks authorization and CSRF protection, enabling unauthorized user deletion.