
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-4521 is a privilege escalation vulnerability in the IDonate – Blood Donation, Request And Donor Management System plugin for WordPress, affecting versions 2.1.5 through 2.1.9. The flaw allows authenticated attackers with Subscriber-level access or higher to hijack any WordPress account by reassigning its email address and triggering a password reset, ultimately granting themselves full administrator privileges. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, Wordfence).
The root cause is a missing capability check (CWE-285: Improper Authorization) on the idonate_donor_profile() function within the IDonate plugin. An authenticated attacker can supply an arbitrary donor_id parameter to this function, which allows them to reassign the email address of any WordPress account — including administrator accounts — to one they control. Once the email is redirected, the attacker triggers a standard WordPress password reset to the now-attacker-controlled address, completing the account takeover. No special configuration or elevated starting privileges beyond a Subscriber-level account are required (Red Hat CVE, Wordfence).
Successful exploitation grants an attacker full WordPress administrator privileges, enabling complete site takeover. This includes the ability to exfiltrate sensitive user data (including donor personal and medical information stored by the plugin), inject malicious content or malware, create backdoor accounts, and pivot to the underlying server if further vulnerabilities exist. All three pillars — confidentiality, integrity, and availability — are fully compromised upon successful exploitation (Red Hat CVE).
As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.04%, indicating a currently low probability of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement (Subscriber-level) make it an attractive target if exploit details become public (Red Hat CVE, Wordfence).
donor_id or user ID associated with a high-privilege account (e.g., administrator) through enumeration or plugin-specific data exposure.idonate_donor_profile(): Send a crafted authenticated request to the vulnerable idonate_donor_profile() function, supplying the target account's donor_id and an attacker-controlled email address as the new email value. The missing capability check allows this update to proceed without authorization.idonate_donor_profile) from low-privilege user sessions.user_email field in the wp_users table for administrator accounts, particularly if the new email domain is unfamiliar; audit trail of wp_usermeta changes correlating with donor profile updates.No patch has been confirmed available for the IDonate plugin versions 2.1.5–2.1.9 at the time of disclosure. Site administrators should immediately deactivate and remove the IDonate plugin until a patched version is released. As a compensating control, review all WordPress user accounts for unauthorized email changes or unexpected administrator-level access, and audit password reset logs for suspicious activity. Restrict or temporarily remove Subscriber-level accounts if not operationally required. Contact the plugin developer (TheMeatelier) for patch availability and timeline (Red Hat CVE, Wordfence).
Wordfence included CVE-2025-4521 in their weekly WordPress vulnerability report for February 16–22, 2026, flagging it as a notable privilege escalation issue (Wordfence). The vulnerability was also noted on social platforms including Mastodon and Bluesky by security news accounts such as TheHackerWire, indicating moderate community awareness. No major vendor statements or high-profile researcher commentary beyond standard advisory coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."