Impact
Missing authorization in the IDonatePro WordPress plugin allows attackers to access functionality that is not properly constrained by access control lists. This broken access control flaw, classified as CWE-862, can enable unauthorized manipulation of donation data, configuration changes, or other privileged actions within a WordPress site.
Affected Systems
All installations of the ThemeAtelier IDonatePro plugin on WordPress platforms running version 2.1.11 or earlier are affected. The vulnerability is present in every release through 2.1.11, regardless of the specific WordPress theme or other plugins used.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves requesting protected plugin endpoints or performing actions that should be limited to administrators, either by a known administrator account or by exploiting weak or missing authentication checks. An attacker who succeeds could gain unauthorized access to sensitive features and data.
OpenCVE Enrichment