IDonate
cpe:2.3:a:themeatelier:idonate:*:*:*:*:wordpress:*:*
- < 2.1.13
A vulnerability in the IDonate WordPress plugin, affecting versions prior to 2.1.13, allows unauthenticated attackers to delete arbitrary users. This issue arises from a lack of authorization and cross-site request forgery (CSRF) protection when users are deleted via an action handler.
Exploitation of this vulnerability allows for the unauthorized deletion of users.
To reproduce this vulnerability, send a POST request to 'wp-admin/admin-ajax.php' with the 'action' parameter set to 'panding_donor_action', the 'target' parameter set to 'delete', and the 'userid' parameter set to a valid numeric User ID. The absence of authorization and CSRF protection in the IDonate WordPress plugin prior to version 2.1.13 enables this exploitation.
Users are advised to update the IDonate WordPress plugin to version 2.1.13 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.