Total Donations WordPress Plugin Vulnerable to SQL Injection and Privilege Escalation
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- total donations (wordpress)
- Patched version
- Not yet available
The Total Donations plugin for WordPress is reportedly vulnerable to SQL Injection and Privilege Escalation in all versions up to, and including, 2.0.5. This vulnerability allows unauthenticated attackers to extract sensitive information and elevate privileges.
What happened
The Total Donations plugin for WordPress is under investigation for a critical vulnerability tracked as CVE-2026-78568. This vulnerability, rated 9.8 on the CVSS scale, allows SQL Injection due to insufficient escaping of user-supplied parameters and inadequate preparation of existing SQL queries. Unauthenticated attackers can exploit this to append additional SQL queries and extract sensitive information from the database.
Additionally, the plugin is also reportedly vulnerable to Privilege Escalation, tracked as CVE-2026-78570. This vulnerability allows unauthenticated attackers to elevate their privileges to that of an administrator, further compromising the security of affected sites.
What to do about it
- Upgrade the Total Donations plugin to a version beyond 2.0.5 if available.
- Remove the Total Donations plugin if it is no longer needed.
- Monitor the provided sources for updates on patched versions and further details.
- Conduct a security audit of your WordPress site to ensure no unauthorized access has occurred.
- Implement additional security measures to protect your database from SQL Injection attacks.
How 0Day would have caught this
total donations is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using the Total Donations plugin for WordPress in versions up to, and including, 2.0.5.
What should I do right now?
Upgrade to a version beyond 2.0.5 or remove the plugin if no longer needed. Monitor the provided sources for updates.
Has this been exploited in the wild?
There is no confirmed report of this vulnerability being exploited in the wild at this time.
Where can I find more information?
Consult the provided CVE links for the latest details and updates.