CVE-2026-78570 (matched: wordpress)

  • Tuesday, 25th August, 2026
  • 22:09pm

A security flaw has been found in the Total Donations plugin for WordPress, a tool many sites use to manage donation campaigns. All versions of this plugin up to and including version 2.0.5 are affected by a privilege escalation issue, which means people who do not have a valid login account for your site can gain full administrator-level access to your WordPress dashboard.

With this level of access, an unapproved user could make any changes to your site, including adjusting donation settings, accessing sensitive information like donor details, posting unwanted content, or taking complete control of your site entirely.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78570

« Back