CVE-2025-32519: WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Foysal Imran IDonate idonate allows PHP Local File Inclusion.This issue affects IDonate: from n/a through <= 2.1.18.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32519?
CVE-2025-32519 is considered a high severity vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-32519?
To fix CVE-2025-32519, update ThemeAtelier IDonate to version 2.1.9 or later.
What potential impact does CVE-2025-32519 have?
CVE-2025-32519 allows attackers to exploit local file inclusion, potentially leading to unauthorized access to sensitive files.
Is CVE-2025-32519 present in earlier versions of IDonate?
Yes, CVE-2025-32519 affects all versions of ThemeAtelier IDonate from n/a through 2.1.8.
Are there specific platforms affected by CVE-2025-32519?
Yes, CVE-2025-32519 impacts the ThemeAtelier IDonate application and the WordPress IDonate plugin up to version 2.1.8.