Executive brief
Donation Thermometer is a WordPress plugin used to display fundraising progress on websites. A security flaw in versions 2.2.7 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators. While the impact is considered low, it could allow an attacker to modify certain plugin settings or data without permission.
Technical details
The Donation Thermometer plugin for WordPress (versions <= 2.2.7) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The vulnerability is exploited via the network without requiring user interaction. According to the advisory, there is currently no official patch available, and the impact is primarily limited to unauthorized integrity changes (CVSS:I:L).
Affected products
- rhewlif Donation Thermometer <= 2.2.7
Timeline
- 2025-10-16: disclosed: Reported by Legion Hunter
- 2026-06-26: advisory: Published by Patchstack and NVD