ThemeAtelier records
8 published records for vendor themeatelier.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-285 Improper Authorization1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-32519No exploit | WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerabilitythemeatelier · idonate · CWE-98 | Critical9.8 | — | 0.9% | Apr 11, 2025 |
35Monitor | CVE-2025-4519No exploit | IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Functionthemeatelier · idonate · CWE-285 | High8.8 | — | 0.3% | Nov 7, 2025 |
34Monitor | CVE-2024-3594No exploit | IDonate <= 1.9.0 - Admin+ Stored XSSthemeatelier · idonate · CWE-79 | High8.7 | — | 0.5% | May 23, 2024 |
26Monitor | CVE-2025-4523No exploit | IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Functionthemeatelier · idonate · CWE-200 | Medium6.5 | — | 0.3% | Aug 1, 2025 |
26Monitor | CVE-2025-4522No exploit | IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Functionthemeatelier · idonate · CWE-862 | Medium6.5 | — | 0.3% | Nov 7, 2025 |
21Monitor | CVE-2025-12877No exploit | IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletionthemeatelier · idonate · CWE-862 | Medium5.3 | — | 0.3% | Nov 22, 2025 |
21Monitor | CVE-2025-67583No exploit | WordPress IDonate plugin <= 2.1.15 - Broken Access Control vulnerabilitythemeatelier · idonate · CWE-862 | Medium5.3 | — | 0.2% | Dec 9, 2025 |
21Monitor | CVE-2025-11154No exploit | IDonate < 2.1.13 - Unauthenticated User Deletionthemeatelier · idonate · CWE-352 | Medium5.4 | — | 0.1% | Oct 27, 2025 |
- CVE-2025-3251939Monitor
WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerability
CriticalCVSS 9.8No exploitEPSS 1%themeatelier · idonateApr 11, 2025
- CVE-2025-451935Monitor
IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function
HighCVSS 8.8No exploitEPSS 0%themeatelier · idonateNov 7, 2025
- CVE-2024-359434Monitor
IDonate <= 1.9.0 - Admin+ Stored XSS
HighCVSS 8.7No exploitEPSS 1%themeatelier · idonateMay 23, 2024
- CVE-2025-452326Monitor
IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function
MediumCVSS 6.5No exploitEPSS 0%themeatelier · idonateAug 1, 2025
- CVE-2025-452226Monitor
IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function
MediumCVSS 6.5No exploitEPSS 0%themeatelier · idonateNov 7, 2025
- CVE-2025-1287721Monitor
IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
MediumCVSS 5.3No exploitEPSS 0%themeatelier · idonateNov 22, 2025
- CVE-2025-6758321Monitor
WordPress IDonate plugin <= 2.1.15 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%themeatelier · idonateDec 9, 2025
- CVE-2025-1115421Monitor
IDonate < 2.1.13 - Unauthenticated User Deletion
MediumCVSS 5.4No exploitEPSS 0%themeatelier · idonateOct 27, 2025