Description
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version before 2.1.13
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/fdb9e076-4c65-4fd1-b1f6-23c23a11bdb7/