Description
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability check on the panding_blood_request_action() function in all versions up to, and including, 2.1.15. This makes it possible for unauthenticated attackers to delete arbitrary posts. CVE-2025-67583 is likely a duplicate of this.
INFO
Published Date :
2025-11-22T07:29:20.354Z
Last Modified :
2026-04-08T17:10:17.376Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2025-12877 vulnerability.
| Vendors | Products |
|---|---|
| Themeatelier |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-12877.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact