CVE-2025-12877: IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

Published Nov 22, 2025
·
Updated

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the pandingbloodrequestaction() function in all versions up to, and including, 2.1.15. This makes it possible for unauthenticated attackers to delete arbitrary posts. CVE-2025-67583 is likely a duplicate of this.

Affected Software

2 affected components
IDonate Blood Donation, Request And Donor Management System<=2.1.15
ThemeAtelier Idonate Wordpress<2.1.16

Event History

Nov 22, 2025
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-12877?

CVE-2025-12877 has a high severity level due to unauthorized data modification risks.

2

How do I fix CVE-2025-12877?

To fix CVE-2025-12877, update the IDonate plugin to version 2.1.16 or later where the vulnerability is patched.

3

What versions of IDonate are affected by CVE-2025-12877?

All versions of the IDonate plugin up to and including 2.1.15 are affected by CVE-2025-12877.

4

What impact does CVE-2025-12877 have on my WordPress site?

CVE-2025-12877 allows unauthorized users to modify blood donation requests, compromising data integrity on your site.

5

Is there a workaround for CVE-2025-12877 if I cannot update?

There is no official workaround for CVE-2025-12877, so updating the plugin is strongly recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203