Junglewise Threat Intelligence

CVE-2025-64636: rhewlif Donation Thermometer broken access control

CVE-2025-64636 · Severity: medium · CVSS 5.3 · Published 2026-06-26

Executive brief

Donation Thermometer is a WordPress plugin used to display fundraising progress on websites. A security flaw in versions 2.2.7 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators. While the impact is considered low, it could allow an attacker to modify certain plugin settings or data without permission.

Technical details

The Donation Thermometer plugin for WordPress (versions <= 2.2.7) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The vulnerability is exploited via the network without requiring user interaction. According to the advisory, there is currently no official patch available, and the impact is primarily limited to unauthorized integrity changes (CVSS:I:L).

Affected products

  • rhewlif Donation Thermometer <= 2.2.7

Timeline

  • 2025-10-16: disclosed: Reported by Legion Hunter
  • 2026-06-26: advisory: Published by Patchstack and NVD

References