criticalOther

Total Donations WordPress Plugin Unauthenticated Privilege Escalation

First seen Aug 26, 2026 · Updated Aug 26, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcms-security

The Total Donations plugin for WordPress (versions up to 2.0.5) contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrator-level access. Given the CVSS score of 9.8, this flaw is trivially exploitable and could lead to full site takeover.

Technical Analysis

CVE-2026-78570 affects the Total Donations plugin for WordPress in all versions up to and including 2.0.5, allowing unauthenticated attackers to escalate privileges to that of an administrator, likely due to improper access control or insecure user role assignment logic within the plugin's donation or account-handling functions. Once administrative access is obtained, attackers can install malicious plugins, modify theme files for persistent backdoors, or pivot to server-level compromise via plugin editor RCE techniques. The vulnerability requires no authentication, making it exploitable via automated scanning and mass exploitation campaigns targeting WordPress sites running the vulnerable plugin. If a compromised WordPress instance hosts or serves content ingested by RAG pipelines, or is used as an integration endpoint for AI agent-driven content management or donation-processing workflows, attacker-controlled admin access could enable injection of malicious instructions, data poisoning, or exposure of API keys/credentials stored in site configuration, warranting agent-relevant monitoring for organizations with such integrations.

Affected Systems

WordPress installations running the Total Donations plugin, all versions up to and including 2.0.5

Indicators of Compromise

  • No specific IOCs published at this time; monitor for anomalous admin account creation and unexpected privilege changes on WordPress sites running Total Donations plugin

Remediation Steps

  1. 1

    Update the Plugin

    Upgrade Total Donations plugin to a patched version beyond 2.0.5 as soon as it becomes available from the vendor.

  2. 2

    Disable or Remove Plugin

    If no patch is available, deactivate and remove the Total Donations plugin until a fix is released.

  3. 3

    Audit Admin Accounts

    Review all administrator accounts for unauthorized additions or privilege changes.

  4. 4

    Implement WAF Rules

    Deploy web application firewall rules to detect and block exploitation attempts targeting this vulnerability.

  5. 5

    Rotate Credentials and API Keys

    If the site integrates with AI agent systems, RAG pipelines, or external APIs, rotate any credentials or keys accessible via the WordPress admin panel.

  6. 6

    Monitor Logs

    Review server and application logs for signs of exploitation, including unusual POST requests or role modification events.

CVE / Advisory IDs

CVE-2026-78570

Industries Most Exposed

Nonprofit/CharityE-commerceMediaAny organization using WordPress for donation processing

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.