Missing Authorization Vulnerability in ThemeAtelier IDonatePro Plugin
CVE-2025-30639

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2025

What is CVE-2025-30639?

A missing authorization vulnerability present in the ThemeAtelier IDonatePro plugin could lead to improperly configured access controls, allowing unauthorized users to exploit various functionalities within the application. This issue impacts versions ranging from n/a to 2.1.9, posing potential risks to systems using the plugin. Website administrators are advised to review their access control configurations and ensure necessary updates are implemented to mitigate this vulnerability.

Affected Version(s)

IDonatePro <= 2.1.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.