A security vulnerability has been identified in the Total Donations plugin for WordPress. The flaw impacts every version of the plugin up to and including version 2.0.5.
This is a privilege escalation issue, which means attackers do not need to have an existing account or login for your website to exploit the flaw. If successfully taken advantage of, these unauthenticated attackers can gain full administrator-level access to your WordPress site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78570