CVE-2025-11154 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers t…
Medium CVSS: 5.4

CVE-2025-11154

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
Vendor
Themeatelier
Product
Idonate
CWE
CWE-352
Yayın Tarihi
2025-10-27 06:15:37
Güncelleme
2025-12-05 00:20:23
Source Identifier
contact@wpscan.com
KEV Date Added
-

Kategoriler

Referanslar