Логотип exploitDog
bind:CVE-2025-11154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-11154

Количество 2

Количество 2

nvd логотип

CVE-2025-11154

7 дней назад

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxxg-8p58-2qqv

7 дней назад

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-11154

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVSS3: 5.4
0%
Низкий
7 дней назад
github логотип
GHSA-xxxg-8p58-2qqv

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVSS3: 5.4
0%
Низкий
7 дней назад

Уязвимостей на страницу