CVE-2025-30639: WordPress IDonatePro Plugin <= 2.1.9 - Broken Access Control Vulnerability
Missing Authorization vulnerability in ThemeAtelier IDonatePro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IDonatePro: from n/a through 2.1.9.
Other sources
Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonatePro: from n/a through <= 2.1.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30639?
CVE-2025-30639 is classified as a missing authorization vulnerability that can lead to unauthorized access.
How do I fix CVE-2025-30639?
To fix CVE-2025-30639, update ThemeAtelier IDonatePro to the latest version beyond 2.1.9.
What software is affected by CVE-2025-30639?
CVE-2025-30639 affects ThemeAtelier IDonatePro versions up to and including 2.1.9.
What types of access does CVE-2025-30639 allow?
CVE-2025-30639 allows attackers to exploit incorrectly configured access control security levels.
Is CVE-2025-30639 present in WordPress IDonatePro Plugin?
Yes, the vulnerability CVE-2025-30639 also affects the WordPress IDonatePro Plugin up to version 2.1.9.