PHP Remote File Inclusion in ThemeAtelier IDonate Affects WordPress Users
CVE-2025-32519

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
11 April 2025

What is CVE-2025-32519?

The ThemeAtelier IDonate plugin for WordPress contains a vulnerability that allows for PHP Local File Inclusion due to improper handling of filename controls in the include or require statements. This flaw affects all versions up to and including 2.1.8, posing a significant risk to sites utilizing this plugin as it allows attackers to potentially execute arbitrary PHP code. Protect your WordPress site by applying necessary patches and monitoring for any unauthorized file inclusions.

Affected Version(s)

IDonate <= 2.1.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.
The Cyber Security Vulnerability Database.