CVE-2026-78568 (matched: wordpress)

  • Tuesday, 25th August, 2026
  • 16:06pm

A security flaw has been identified in the Total Donations plugin for WordPress, a tool many sites use to accept and manage online donations. The flaw, a type of bug called SQL injection, affects all versions of the plugin up to and including version 2.0.5.

This issue occurs because the plugin does not properly filter input provided by site visitors before using it in database queries. Attackers do not need to have a login or any pre-existing access to your site to exploit this flaw.

If exploited, an attacker can add extra commands to the plugin's existing database queries to extract sensitive information stored in your site's database, such as donor personal details, payment records, or other private data linked to your site and its users.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78568

« Back