CVE-2025-4521Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_profile() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to hijack any account by reassigning its email address (via the donor_id they supply) and then triggering a password reset, ultimately granting themselves full administrator privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-4521** pertains to a privilege escalation flaw in the **IDonate – Blood Donation, Request And Donor Management System** plugin for WordPress, specifically affecting versions **2.1.5 to 2.1.9**. The core issue lies in the `idonate_donor_profile()` function, which lacks proper capability checks, allowing authenticated users with Subscriber-level access or higher to manipulate donor profiles maliciously. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-4521

    Post summary

    CVE‑2025‑4521 exposes a privilege escalation flaw in the IDonate WordPress plugin (v2.1.5‑2.1.9) by skipping capability checks in the idonate_donor_profile() function, allowing authenticated users to manipulate donor profiles.

    0000036
    20 followersView on X

Explore more