SQL Injection Vulnerability in Total Donations Plugin for WordPress
CVE-2026-78568
9.8CRITICAL
What is CVE-2026-78568?
The Total Donations plugin for WordPress suffers from a SQL Injection vulnerability due to inadequate escaping of user-supplied parameters and poor preparation of SQL queries. This flaw allows unauthenticated attackers to inject additional SQL commands into existing queries, potentially leading to unauthorized access and exposure of sensitive database information. Effective measures should be taken to upgrade to the latest version and ensure all security practices are followed to mitigate this risk.
Affected Version(s)
Total Donations 0 <= 2.0.5