PatchSiren cyber security CVE debrief
CVE-2025-22715 loopus CVE debrief
A Missing Authorization vulnerability in the WP Attractive Donations System - Easy Stripe & Paypal donations plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations versions from n/a through 1.25. The vulnerability could lead to potential unauthorized actions on the plugin, emphasizing the need for verification and updates to prevent exploitation. Defenders should review access control security levels and configure them appropriately.
- Vendor
- loopus
- Product
- WP Attractive Donations System - Easy Stripe & Paypal donations
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-08
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-08
- Advisory updated
- 2026-09-30
Who should care
Defenders and administrators using the WP Attractive Donations System plugin should assess exposure and prioritize verification and updates. They should review access control security levels, configure them appropriately, and monitor for potential unauthorized actions on the plugin. Security teams and vulnerability management teams should also be aware of this vulnerability and take necessary actions to prevent exploitation.
Why it matters
Defenders should care about CVE-2025-22715 because it affects the WP Attractive Donations System plugin, potentially allowing unauthorized actions. Verification and updates are necessary to prevent exploitation.
- Potential unauthorized actions on the plugin.
- Verification of access control security levels is necessary.
- Updating the plugin to the latest version is recommended.
Technical summary
The WP Attractive Donations System - Easy Stripe & Paypal donations plugin has a Missing Authorization vulnerability, which allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 1.25. The vulnerability could lead to potential unauthorized actions on the plugin, emphasizing the need for verification and updates to prevent exploitation. Defenders should review access control security levels and configure them appropriately to mitigate potential risks. The plugin's authorization flaw could be exploited to perform unauthorized actions, highlighting the importance of prompt verification and updates.
Defensive priority
Defenders should prioritize verifying and updating the WP Attractive Donations System plugin to prevent potential unauthorized actions.
Recommended defensive actions
- Verify and update the WP Attractive Donations System plugin to the latest version.
- Review and configure access control security levels for the plugin.
- Monitor for potential unauthorized actions on the plugin.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected versions is limited. Defenders should verify the plugin version and review access control configurations to ensure they are not exposed to unauthorized actions. The CVE Program and NVD entries offer official details, but further verification is necessary due to limited information on exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-22715 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-22715
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-22715 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-22715
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.