CVE-2025-60045: WordPress IDonatePro plugin <= 2.1.11 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects IDonatePro: from n/a through <= 2.1.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60045?
CVE-2025-60045 is considered a critical vulnerability due to its potential to allow unauthorized access to sensitive functionalities.
How do I fix CVE-2025-60045?
To fix CVE-2025-60045, update ThemeAtelier IDonatePro to the latest version beyond 2.1.11 where the vulnerability has been addressed.
What are the consequences of exploiting CVE-2025-60045?
Exploiting CVE-2025-60045 can lead to unauthorized access to functionalities, potentially allowing attackers to manipulate or disclose sensitive data.
Is CVE-2025-60045 present in all versions of IDonatePro?
CVE-2025-60045 affects all versions of IDonatePro up to and including version 2.1.11.
Who is affected by CVE-2025-60045?
Any users of ThemeAtelier IDonatePro versions 2.1.11 or earlier are affected by CVE-2025-60045.