CVE-2025-12877: IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the pandingbloodrequestaction() function in all versions up to, and including, 2.1.15. This makes it possible for unauthenticated attackers to delete arbitrary posts. CVE-2025-67583 is likely a duplicate of this.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12877?
CVE-2025-12877 has a high severity level due to unauthorized data modification risks.
How do I fix CVE-2025-12877?
To fix CVE-2025-12877, update the IDonate plugin to version 2.1.16 or later where the vulnerability is patched.
What versions of IDonate are affected by CVE-2025-12877?
All versions of the IDonate plugin up to and including 2.1.15 are affected by CVE-2025-12877.
What impact does CVE-2025-12877 have on my WordPress site?
CVE-2025-12877 allows unauthorized users to modify blood donation requests, compromising data integrity on your site.
Is there a workaround for CVE-2025-12877 if I cannot update?
There is no official workaround for CVE-2025-12877, so updating the plugin is strongly recommended.