CVE-2025-30639

7.5

ThemeAtelier · IDonatePro

A missing authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin allows unauthenticated users to exploit incorrectly configured access control security levels.

Executive summary

A critical authorization bypass vulnerability in ThemeAtelier IDonatePro allows unauthenticated attackers to manipulate sensitive access control settings, posing a significant risk to site integrity.

Vulnerability

This vulnerability is caused by a missing authorization check (CWE-862) in the IDonatePro plugin, which allows unauthenticated remote attackers to bypass intended security restrictions and interact with restricted plugin functions.

Business impact

The ability for an unauthenticated user to bypass access controls can lead to unauthorized modification of site settings or data, potentially compromising the integrity of the WordPress installation. Given the CVSS score of 7.5, this high-severity flaw poses a substantial risk to business operations, as it could be leveraged to gain administrative-like control over plugin-specific features.

Remediation

Immediate Action: Since no specific patch version is currently identified, users should immediately disable or remove the IDonatePro plugin until a security update is released by the vendor.

Proactive Monitoring: Review web server and WordPress access logs for anomalous requests directed at plugin-specific endpoints, particularly those originating from unauthorized or unknown IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts to plugin directories, which may help mitigate exploitation attempts until the software is updated.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The presence of a missing authorization flaw in a plugin that handles site donations and potentially sensitive data presents an unacceptable risk to organizational security. Administrators must prioritize the immediate deactivation of the affected software and monitor official vendor channels for the release of a patched version. Applying the update as soon as it becomes available is the only definitive way to resolve this access control failure.

More ThemeAtelier CVEs

Sources

Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.