A security vulnerability has been found in the Total Donations plugin for WordPress, impacting all versions of the plugin up to and including version 2.0.5. This flaw is a privilege escalation issue, meaning attackers who do not have any existing login credentials for your WordPress site can gain full administrator-level access to your site. With this level of access, bad actors could take full control of your site, including changing its content, accessing private data, or disrupting its operation entirely.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-78570