← WordPress Vulnerabilities
WordPress security by component

IDonate – Blood Donation, Request And Donor Management System

IDonate – Blood Donation, Request And Donor Management System is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Feb 19, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: idonate

CVE-2025-4521: IDonate – Blood Donation, Request And Donor Management System: Privilege escalation or authentication bypass

IDonate – Blood Donation, Request And Donor Management System is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.

PublishedFeb 19, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 19, 2026 CVE-2025-4521
IDonate – Blood Donation, Request And Donor Management System: Privilege escalation or authentication bypass
IDonate – Blood Donation, Request And Donor Management System is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Dec 09, 2025 CVE-2025-67583
IDonate: A security weakness
IDonate is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 22, 2025 CVE-2025-12877
IDonate – Blood Donation, Request And Donor Management System: A security weakness
IDonate – Blood Donation, Request And Donor Management System is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 07, 2025 CVE-2025-4522
IDonate – Blood Donation, Request And Donor Management System: A security weakness
IDonate – Blood Donation, Request And Donor Management System is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Nov 07, 2025 CVE-2025-4519
IDonate – Blood Donation, Request And Donor Management System: Privilege escalation or authentication bypass
IDonate – Blood Donation, Request And Donor Management System is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Oct 27, 2025 CVE-2025-11154
IDonate: Cross-site request forgery
IDonate is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Aug 01, 2025 CVE-2025-4523
IDonate – Blood Donation, Request And Donor Management System: A security weakness
IDonate – Blood Donation, Request And Donor Management System is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Apr 11, 2025 CVE-2025-32519
IDonate: Filesystem traversal
IDonate is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVD9.8
May 23, 2024 CVE-2024-3594
IDonate: Cross-site scripting
IDonate is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE8.7
NVDPending