
**CVE-2025-4521** pertains to a privilege escalation flaw in the **IDonate – Blood Donation, Request And Donor Management System** plugin for WordPress, specifically affecting versions **2.1.5 to 2.1.9**. The core issue lies in the `idonate_donor_profile()` function, which lacks proper capability checks, allowing authenticated users with Subscriber-level access or higher to manipulate donor profiles maliciously. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-4521
Post summary
CVE‑2025‑4521 exposes a privilege escalation flaw in the IDonate WordPress plugin (v2.1.5‑2.1.9) by skipping capability checks in the idonate_donor_profile() function, allowing authenticated users to manipulate donor profiles.
