Total Donations WordPress Plugin Unauthenticated Privilege Escalation
First seen Aug 26, 2026 · Updated Aug 26, 2026 · CVSS 9.8
The Total Donations plugin for WordPress (versions up to 2.0.5) contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrator-level access. Given the CVSS score of 9.8, this flaw is trivially exploitable and could lead to full site takeover.
Technical Analysis
CVE-2026-78570 affects the Total Donations plugin for WordPress in all versions up to and including 2.0.5, allowing unauthenticated attackers to escalate privileges to that of an administrator, likely due to improper access control or insecure user role assignment logic within the plugin's donation or account-handling functions. Once administrative access is obtained, attackers can install malicious plugins, modify theme files for persistent backdoors, or pivot to server-level compromise via plugin editor RCE techniques. The vulnerability requires no authentication, making it exploitable via automated scanning and mass exploitation campaigns targeting WordPress sites running the vulnerable plugin. If a compromised WordPress instance hosts or serves content ingested by RAG pipelines, or is used as an integration endpoint for AI agent-driven content management or donation-processing workflows, attacker-controlled admin access could enable injection of malicious instructions, data poisoning, or exposure of API keys/credentials stored in site configuration, warranting agent-relevant monitoring for organizations with such integrations.
Affected Systems
WordPress installations running the Total Donations plugin, all versions up to and including 2.0.5
Indicators of Compromise
- No specific IOCs published at this time; monitor for anomalous admin account creation and unexpected privilege changes on WordPress sites running Total Donations plugin
Remediation Steps
- 1
Update the Plugin
Upgrade Total Donations plugin to a patched version beyond 2.0.5 as soon as it becomes available from the vendor.
- 2
Disable or Remove Plugin
If no patch is available, deactivate and remove the Total Donations plugin until a fix is released.
- 3
Audit Admin Accounts
Review all administrator accounts for unauthorized additions or privilege changes.
- 4
Implement WAF Rules
Deploy web application firewall rules to detect and block exploitation attempts targeting this vulnerability.
- 5
Rotate Credentials and API Keys
If the site integrates with AI agent systems, RAG pipelines, or external APIs, rotate any credentials or keys accessible via the WordPress admin panel.
- 6
Monitor Logs
Review server and application logs for signs of exploitation, including unusual POST requests or role modification events.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.