Total Donations
by WordPress
Source repositories
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-6703 | Cri | 0.66 | 9.8 | 0.26 | Jan 27, 2019 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to… | ||
| CVE-2026-78570 | Cri | 0.64 | 9.8 | — | Aug 25, 2026 | The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator. | ||
| CVE-2026-78568 | Cri | 0.64 | 9.8 | — | Aug 25, 2026 | The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | ||
| CVE-2026-73390 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | ||
| CVE-2026-73391 | Cri | 0.60 | 9.3 | 0.00 | Aug 19, 2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | ||
| CVE-2025-43837 | Hig | 0.46 | 7.1 | 0.00 | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations total-donations allows Reflected XSS.This issue affects Total Donations: from n/a through <= 3.0.8. |
- risk 0.66cvss 9.8epss 0.26
Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to…
- risk 0.64cvss 9.8epss —
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator.
- risk 0.64cvss 9.8epss —
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations total-donations allows Reflected XSS.This issue affects Total Donations: from n/a through <= 3.0.8.