IDonate WordPress Plugin Unauthenticated User Deletion Vulnerability (CVE-2025-11154) — Medium Severity

In the dynamic world of web security, staying ahead of potential threats is paramount, especially for WordPress site administrators. A recent discovery has brought to light a significant security vulnerability, CVE-2025-11154, affecting the popular IDonate WordPress plugin. This plugin, widely used by organizations and individuals to facilitate online donations, has been found to have a critical flaw that could put your website’s user management at risk.

At its core, this vulnerability allows an unauthorized person to delete users from your WordPress site. What makes this particularly concerning is that an attacker doesn’t need to log in or possess any specific authentication credentials to exploit it. They can simply manipulate an action handler within the plugin to execute user deletion commands. This ‘unauthenticated’ nature means the attack can be launched by anyone, significantly broadening the potential threat landscape. Imagine the chaos if a malicious individual could remove legitimate donors, administrators, or any registered user from your platform without detection or permission.

CVE Details

  • Product: IDonate WordPress Plugin
  • Published Date: October 27, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

This specific security weakness is present in versions of the IDonate WordPress plugin that are older than 2.1.13. If your WordPress installation relies on the IDonate plugin and you haven’t updated it recently, it is highly probable that your site is exposed to this unauthenticated user deletion vulnerability. Checking your plugin version and updating is an urgent priority.

Current Status

Following its discovery, this vulnerability has been thoroughly analyzed by security researchers. The good news for IDonate users is that a patch has been developed and released. The issue is officially resolved in version 2.1.13 of the IDonate WordPress plugin. This swift action provides a clear path for users to secure their websites against this threat.

Severity Level

The National Vulnerability Database (NVD) has categorized CVE-2025-11154 with a “Medium” severity rating. However, it’s crucial to note that the CVSS v3.1 score, often a more detailed measure, provided by WPScan for this vulnerability is 8.2, which falls into the “High” severity bracket. This higher score is a strong indicator of the serious risks involved. A high CVSS score typically means that the vulnerability is relatively straightforward for an attacker to exploit, requires no special access or knowledge, and can lead to significant impacts, such as a complete loss of integrity or availability of user accounts on your website. The lack of authorization and Cross-Site Request Forgery (CSRF) protection makes it particularly easy for an attacker to craft a request that deletes users.

Possible Solutions

The primary and most effective solution to mitigate the risk posed by CVE-2025-11154 is to update your IDonate WordPress plugin immediately. Ensure you upgrade to version 2.1.13 or any subsequent release. These versions contain the essential security fixes that prevent unauthorized users from deleting accounts on your site.

Beyond this specific update, adopting a proactive cybersecurity strategy is vital for any WordPress website owner or administrator:

  • Regular Updates: Make it a habit to keep your WordPress core, all themes, and all plugins updated to their latest versions. Developers frequently release updates that include critical security patches.
  • Robust Backup Strategy: Implement a consistent and reliable backup schedule for your entire website. In the event of a security incident, a recent backup can be your most valuable asset for quick recovery.
  • Strong Authentication: Enforce strong, complex passwords for all user accounts, especially those with administrative privileges. Consider implementing two-factor authentication (2FA) for an added layer of security.
  • Security Plugins & Firewalls: Utilize reputable WordPress security plugins and, if possible, a Web Application Firewall (WAF) to detect and block malicious traffic before it reaches your site.
  • Principle of Least Privilege: Grant users only the minimum necessary permissions required for their roles. This limits the potential damage if an account is compromised.

References

https://wpscan.com/vulnerability/fdb9e076-4c65-4fd1-b1f6-23c23a11bdb7/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.