Understanding the Donations WordPress Plugin SQL Injection Vulnerability
A notable security flaw has been found in the Donations WordPress plugin, affecting versions up to and including 1.0. This vulnerability, identified as CVE-2025-13001, is a SQL Injection issue that could allow malicious actors to compromise your website’s database.
Specifically, the plugin fails to properly clean and secure user-provided information before using it in a database query. This oversight opens the door for high-privilege users, such as administrators, to inject harmful SQL code into the system. If exploited, this could lead to unauthorized access to sensitive data, modification of database content, or even complete control over the affected WordPress site.
CVE Details
Product: Donations WordPress Plugin
CVE ID: CVE-2025-13001
Published Date: December 2, 2025
Severity: Medium
Affected Products
The SQL Injection vulnerability impacts the Donations WordPress plugin through version 1.0. If you are using this plugin, especially an outdated version, your website could be at risk.
Current Status
This vulnerability has been Analyzed. Security researchers have thoroughly examined the flaw and confirmed its existence and potential impact.
Severity Level
Rated as Medium severity, this vulnerability presents a significant risk. While it requires high-privilege access (like an administrator account) to exploit, a compromised admin account could lead to severe consequences for your website. Successful exploitation could result in unauthorized data access, manipulation, or even a complete takeover of your site.
Possible Solutions
As of the latest information, there is No known fix or patch available for the Donations WordPress plugin version 1.0 to address this SQL Injection vulnerability. If you are using this plugin, it is highly recommended to:
- Deactivate and remove the plugin immediately until a secure update is released by the developer.
- Look for alternative, well-maintained donation plugins from trusted sources.
- Regularly backup your website to minimize data loss in case of an attack.
- Implement strong security practices for your WordPress admin accounts, including unique, complex passwords and two-factor authentication.
- Monitor your website for any unusual activity.
References
https://wpscan.com/vulnerability/4e7a8154-46bf-44c9-ad9a-273e99ae2104/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13001


