Description
Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonatePro: from n/a through <= 2.1.9.
Published: 2025-08-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IDonatePro plugin for WordPress contains a missing authorization flaw that permits attackers to bypass configured access controls. This vulnerability can be used to gain privileges that should be limited to administrators, allowing the attacker to modify plugin settings, upload and execute files, or potentially alter website content. The weakness is identified as CWE‑862, a breach of proper authorization checks, and could lead to a compromise of confidentiality, integrity, or availability of the website.

Affected Systems

The flaw affects ThemeAtelier IDonatePro releases up through version 2.1.9. Users running any version of the plugin from the initial release to 2.1.9 are impacted. No specific environment or operating system is required beyond a standard WordPress installation that has this plugin installed and active.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high risk level when exploited. The EPSS score is reported as less than 1%, suggesting exploitation is currently unlikely or only a small fraction of the landscape attempts to exploit it. It is not listed in the CISA KEV catalog. That said, the attack vector is inferred to be via the web interface, where an attacker can send crafted requests to the plugin’s administrative endpoints without proper role verification. If successfully exploited, the attacker could assume administrative permissions, which could be leveraged for further site compromise or data exfiltration.

Generated by OpenCVE AI on April 30, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update IDonatePro to the latest release that removes the access control flaw.
  • Limit the capabilities granted to users that interact with the IDonatePro plugin to the absolute minimum required for their role.
  • Apply a web‑application firewall rule or WordPress security plugin setting that blocks non‑administrator requests from accessing IDonatePro’s administrative URLs until the plugin is updated.

Generated by OpenCVE AI on April 30, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24739 Missing Authorization vulnerability in ThemeAtelier IDonatePro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IDonatePro: from n/a through 2.1.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ThemeAtelier IDonatePro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IDonatePro: from n/a through 2.1.9. Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonatePro: from n/a through <= 2.1.9.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeatelier
Themeatelier idonate
Wordpress
Wordpress wordpress
Vendors & Products Themeatelier
Themeatelier idonate
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ThemeAtelier IDonatePro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IDonatePro: from n/a through 2.1.9.
Title WordPress IDonatePro Plugin <= 2.1.9 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Themeatelier Idonate
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:56.731Z

Reserved: 2025-03-24T13:01:06.202Z

Link: CVE-2025-30639

cve-icon Vulnrichment

Updated: 2025-08-14T13:28:58.821Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:32.760

Modified: 2026-04-23T15:27:01.290

Link: CVE-2025-30639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T16:30:16Z

Weaknesses