CVE-2025-4521: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-4521 is a privilege escalation vulnerability in the IDonate – Blood Donation, Request And Donor Management System plugin for WordPress, affecting versions 2.1.5 through 2.1.9. The flaw allows authenticated attackers with Subscriber-level access or higher to hijack any WordPress account by reassigning its email address and triggering a password reset, ultimately granting themselves full administrator privileges. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is a missing capability check (CWE-285: Improper Authorization) on the idonate_donor_profile() function within the IDonate plugin. An authenticated attacker can supply an arbitrary donor_id parameter to this function, which allows them to reassign the email address of any WordPress account — including administrator accounts — to one they control. Once the email is redirected, the attacker triggers a standard WordPress password reset to the now-attacker-controlled address, completing the account takeover. No special configuration or elevated starting privileges beyond a Subscriber-level account are required (Red Hat CVE, Wordfence).

Impact

Successful exploitation grants an attacker full WordPress administrator privileges, enabling complete site takeover. This includes the ability to exfiltrate sensitive user data (including donor personal and medical information stored by the plugin), inject malicious content or malware, create backdoor accounts, and pivot to the underlying server if further vulnerabilities exist. All three pillars — confidentiality, integrity, and availability — are fully compromised upon successful exploitation (Red Hat CVE).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.04%, indicating a currently low probability of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement (Subscriber-level) make it an attractive target if exploit details become public (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the IDonate plugin versions 2.1.5–2.1.9 using tools like WPScan, Shodan, or by inspecting plugin directories on target sites.
  2. Account Registration: Register or obtain a Subscriber-level (or higher) account on the target WordPress site, as the vulnerability requires authentication.
  3. Identify Target Account: Determine the donor_id or user ID associated with a high-privilege account (e.g., administrator) through enumeration or plugin-specific data exposure.
  4. Email Hijack via idonate_donor_profile(): Send a crafted authenticated request to the vulnerable idonate_donor_profile() function, supplying the target account's donor_id and an attacker-controlled email address as the new email value. The missing capability check allows this update to proceed without authorization.
  5. Trigger Password Reset: Use WordPress's standard password reset functionality to send a reset link to the now-attacker-controlled email address associated with the administrator account.
  6. Complete Account Takeover: Follow the password reset link received in the attacker's email inbox, set a new password, and log in as the administrator to achieve full site control (Red Hat CVE, Wordfence).

Indicators of compromise

  • Logs: WordPress authentication logs showing Subscriber-level accounts logging in with administrator privileges; password reset emails sent to unexpected or newly changed email addresses for administrator accounts; access logs showing POST requests to IDonate plugin endpoints (e.g., functions related to idonate_donor_profile) from low-privilege user sessions.
  • Database: Unexpected changes to the user_email field in the wp_users table for administrator accounts, particularly if the new email domain is unfamiliar; audit trail of wp_usermeta changes correlating with donor profile updates.
  • WordPress Admin: Presence of new administrator accounts not created by legitimate site owners; changes to site settings, installed plugins, or themes made by accounts that should not have admin access.
  • Network: Outbound password reset email traffic to external or newly registered email domains not previously associated with admin accounts.

Mitigation and workarounds

No patch has been confirmed available for the IDonate plugin versions 2.1.5–2.1.9 at the time of disclosure. Site administrators should immediately deactivate and remove the IDonate plugin until a patched version is released. As a compensating control, review all WordPress user accounts for unauthorized email changes or unexpected administrator-level access, and audit password reset logs for suspicious activity. Restrict or temporarily remove Subscriber-level accounts if not operationally required. Contact the plugin developer (TheMeatelier) for patch availability and timeline (Red Hat CVE, Wordfence).

Community reactions

Wordfence included CVE-2025-4521 in their weekly WordPress vulnerability report for February 16–22, 2026, flagging it as a notable privilege escalation issue (Wordfence). The vulnerability was also noted on social platforms including Mastodon and Bluesky by security news accounts such as TheHackerWire, indicating moderate community awareness. No major vendor statements or high-profile researcher commentary beyond standard advisory coverage have been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management