Privilege Escalation Vulnerability in IDonate Plugin for WordPress
CVE-2025-4521
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-4521?
The IDonate β Blood Donation, Request And Donor Management System plugin for WordPress suffers from a Privilege Escalation vulnerability due to inadequate capability checks in the idonate_donor_profile() function. This flaw allows authenticated users with Subscriber-level access or higher to exploit the functionality by modifying the email address of any donor profile they choose. Subsequently, the attacker can initiate a password reset, ultimately gaining full administrator privileges over the affected account. Security for WordPress users utilizing the IDonate plugin has become paramount given this significant risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
IDonate β Blood Donation, Request And Donor Management System 2.1.5 <= 2.1.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved