CVE-2026-78570
9.8KlbTheme · Total Donations
The Total Donations plugin for WordPress is vulnerable to unauthenticated privilege escalation, allowing remote attackers to gain administrative access.
Executive summary
The Total Donations plugin for WordPress contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrative control over the affected site.
Vulnerability
The plugin suffers from improper privilege management, which allows unauthenticated attackers to manipulate user roles. This vulnerability can be leveraged to escalate an attacker's privileges to that of an administrator.
Business impact
This vulnerability carries a CVSS score of 9.8, reflecting its high impact and ease of exploitability. An attacker obtaining administrative access can compromise sensitive data, modify site content, or inject malicious scripts, potentially leading to total site compromise and significant reputational damage.
Remediation
Immediate Action: As no patched version is currently available, administrators should immediately deactivate and remove the Total Donations plugin until a secure update is released by KlbTheme.
Proactive Monitoring: Audit user accounts for unauthorized administrative accounts created or modified recently and review security logs for suspicious login activity.
Compensating Controls: Use a Web Application Firewall (WAF) to block suspicious requests targeting plugin-specific AJAX actions or administrative endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the lack of a vendor-provided patch, the most effective mitigation is the immediate removal of the affected plugin. Administrators must ensure that no unauthorized administrative accounts exist and maintain a heightened state of vigilance for any attempts to manipulate user permissions.