Extension WordPress

Vulnérabilités IDonate – Blood Donation, Request And Donor Management System

Cette page rassemble les failles publiées pour IDonate – Blood Donation, Request And Donor Management System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
1Critiques
7Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de IDonate – Blood Donation, Request And Donor Management System

9 fiches

CVE-2025-4521 Élevée · 8,8
IDonate – Blood Donation, Request And Donor Management System

IDonate 2.1.5 – 2.1.9 – Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_profile Function

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_profile() function in versions 2.1.5 to 2.1.9. This makes it possible for…

Versions affectées

2.1.5-2.1.9

Correctif

2.1.0

Publication

18/02/2026

CVE-2025-12877 Moyenne · 5,3
IDonate – Blood Donation, Request And Donor Management System

IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 – Missing Authorization to Unauthenticated Arbitrary Post Deletion

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the panding_blood_request_action() function in all versions up to, and including, 2.1.15.…

Versions affectées

*-2.1.14

Correctif

2.1.16

Publication

21/11/2025

CVE-2025-4522 Moyenne · 6,5
IDonate – Blood Donation, Request And Donor Management System

IDonate 2.0.0 – 2.1.9 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary user_id parameter value to the…

Versions affectées

2.0.0-2.1.9

Correctif

2.1.10

Publication

06/11/2025

CVE-2025-4519 Élevée · 8,8
IDonate – Blood Donation, Request And Donor Management System

IDonate 2.1.5 – 2.1.9 – Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This makes it possible for…

Versions affectées

2.1.5-2.1.9

Correctif

2.1.10

Publication

06/11/2025

CVE-2025-4523 Moyenne · 6,5
IDonate – Blood Donation, Request And Donor Management System

IDonate 2.0.0 – 2.1.9 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the admin_donor_profile_view() function in versions 2.0.0 to 2.1.9. This makes it…

Versions affectées

2.0.0-2.1.9

Correctif

2.1.10

Publication

31/07/2025

CVE-2025-32519 Critique · 9,8
IDonate – Blood Donation, Request And Donor Management System

IDonate <= 2.1.9 – Unauthenticated Local File Inclusion

The IDonate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.9. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…

Versions affectées

*-2.1.9

Correctif

Non indiqué

Publication

09/04/2025

CVE-2024-3594 Moyenne · 4,4
IDonate – Blood Donation, Request And Donor Management System

IDonate – blood request management system <= 1.9.1 – Authenticated (Admin+) Stored Cross-Site Scripting

The IDonate – blood request management system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.9.1

Correctif

2.0.0

Publication

01/05/2024

CVE-2024-32110 Moyenne · 4,3
IDonate – Blood Donation, Request And Donor Management System

Appsero <= 2.0.0 – Missing Authorization via handle_optin_optout

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated…

Versions affectées

*-2.1.15

Correctif

Non indiqué

Publication

11/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités