Skip to content
Noroxi

ThemeAtelier records

8 published records for vendor themeatelier.

All records

8 records
  • WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    themeatelier · idonateApr 11, 2025

  • CVE-2025-4519
    35Monitor

    IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function

    HighCVSS 8.8No exploitEPSS 0%

    themeatelier · idonateNov 7, 2025

  • CVE-2024-3594
    34Monitor

    IDonate <= 1.9.0 - Admin+ Stored XSS

    HighCVSS 8.7No exploitEPSS 1%

    themeatelier · idonateMay 23, 2024

  • CVE-2025-4523
    26Monitor

    IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function

    MediumCVSS 6.5No exploitEPSS 0%

    themeatelier · idonateAug 1, 2025

  • CVE-2025-4522
    26Monitor

    IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function

    MediumCVSS 6.5No exploitEPSS 0%

    themeatelier · idonateNov 7, 2025

  • IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

    MediumCVSS 5.3No exploitEPSS 0%

    themeatelier · idonateNov 22, 2025

  • WordPress IDonate plugin <= 2.1.15 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    themeatelier · idonateDec 9, 2025

  • IDonate < 2.1.13 - Unauthenticated User Deletion

    MediumCVSS 5.4No exploitEPSS 0%

    themeatelier · idonateOct 27, 2025