Themeatelier's vulnerability profile centers on its donation-management product idonate, a web application handling sensitive donor and transaction data. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through authorization and access-control weakness classes—including missing authorization, improper access control, CSRF, PHP remote file inclusion, and exposure of sensitive information—that are characteristic of web applications managing privileged functionality and user data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themeatelier over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4519HIGH The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_ | Nov 7, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-32519CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Foysal Imran IDonate idonate allows PHP Local File Inclusio | Apr 11, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-3594HIGH The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scr | May 23, 2024 | 8.7 | 24 | NO | NO |
CVE-2025-4523MEDIUM The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the admin_d | Aug 1, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-12877MEDIUM The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the p | Nov 22, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-4522MEDIUM The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function | Nov 7, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-11154MEDIUM The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary u | Oct 27, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-67583MEDIUM Missing Authorization vulnerability in Foysal Imran IDonate idonate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonate: from n/a thr | Dec 9, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themeatelier.
Media articles that mention a CVE ID that affects a product developed by Themeatelier — matched by CVE ID, not by vendor name.