IDonate Blood Donation Privilege Escalation Vulnerability (CVE-2025-4519) — High Severity

Understanding the High-Severity IDonate Vulnerability

A significant security flaw has been discovered in the IDonate – Blood Donation, Request And Donor Management System plugin for WordPress. This vulnerability, tracked as CVE-2025-4519, could allow unauthorized individuals to gain control of your website. It’s crucial for anyone using this plugin to understand the risk and take immediate action.

CVE Details

The affected product is the IDonate – Blood Donation, Request And Donor Management System plugin for WordPress. The vulnerability was published on November 7, 2025, and has a High severity rating. The current status of this vulnerability is Analyzed.

Affected Products

This privilege escalation vulnerability impacts versions 2.1.5 through 2.1.9 of the IDonate – Blood Donation, Request And Donor Management System plugin for WordPress. If you are using any of these versions, your website is at risk.

Current Status

The vulnerability has been Analyzed, meaning its details and impact have been thoroughly investigated. Developers have identified the root cause and released a fix.

Severity Level

Rated as High severity with a CVSS score of 8.8, this vulnerability poses a significant threat. It allows authenticated attackers, even those with basic Subscriber-level access, to trigger a password reset for any user, including administrators. This effectively grants them the ability to elevate their privileges and potentially take full control of the affected website.

Possible Solutions

The good news is that a fix for this vulnerability is available. The issue stems from a missing capability check in the idonate_donor_password() function. The developers have addressed this in version 2.1.10 of the plugin. It is strongly recommended that all users of the IDonate plugin running affected versions update immediately to version 2.1.10 or later.

You can find the changes addressing this vulnerability in the plugin’s development logs, which show the introduction of proper capability checks to prevent unauthorized password resets.

References

https://plugins.trac.wordpress.org/browser/idonate/tags/2.1.9/src/Helpers/DonorFunctions.php#L410

https://plugins.trac.wordpress.org/changeset/3334424/idonate/tags/2.1.10/src/Helpers/DonorFunctions.php?old=3279142&old_path=idonate%2Ftags%2F2.1.9%2Fsrc%2FHelpers%2FDonorFunctions.php

IDonate – Blood Donation, Request And Donor Management System

https://www.wordfence.com/threat-intel/vulnerabilities/id/596aef67-582a-4506-bae9-c7be1899e47a?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.