CVE-2025-11154EPSS p3.1%

CVE-2025-11154CVE-2025-11154

themeatelier / idonate

Description

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

Scoring

CVSS 5.4 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS0.14% probability of exploitation · percentile 3.1% · 2026-10-10T12:00:23Z
Last modified2026-10-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.