CVE-2025-4523: IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the admindonorprofileview() function in versions 2.0.0 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose an administrator’s username, email address, and all donor fields.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4523?
CVE-2025-4523 is considered a medium severity vulnerability due to unauthorized data access risks.
How do I fix CVE-2025-4523?
To fix CVE-2025-4523, update the IDonate plugin to version 2.2.0 or later where the capability checks have been properly implemented.
Who is affected by CVE-2025-4523?
CVE-2025-4523 affects users of the IDonate plugin for WordPress versions 2.0.0 to 2.1.9.
Can CVE-2025-4523 be exploited?
Yes, CVE-2025-4523 can be exploited by authenticated users to gain unauthorized access to sensitive donor information.
What should I do if I can't immediately update for CVE-2025-4523?
If immediate updates are not possible, consider disabling the IDonate plugin until a patch can be applied to mitigate the risks from CVE-2025-4523.