CVE-2025-4519: IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonatedonorpassword() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate a password reset for any user (including administrators) and elevate their privileges for full site takeover.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4519?
CVE-2025-4519 has a medium severity level due to its potential for privilege escalation without proper capability checks.
How do I fix CVE-2025-4519?
To fix CVE-2025-4519, update the IDonate plugin to version 2.1.10 or later where this vulnerability is addressed.
Who is affected by CVE-2025-4519?
CVE-2025-4519 affects WordPress sites using the IDonate plugin versions 2.1.5 to 2.1.9.
What kind of vulnerability is CVE-2025-4519?
CVE-2025-4519 is a privilege escalation vulnerability that allows authenticated attackers to exploit the idonate_donor_password() function.
What versions of IDonate are vulnerable to CVE-2025-4519?
The affected versions of the IDonate plugin for WordPress are from 2.1.5 up to and including 2.1.9.