Summary
CVE-2026-78570 is a critical improper privilege management vulnerability in the Total Donations WordPress plugin by KlbTheme, affecting all versions up to and including 2.0.5. The flaw allows unauthenticated attackers to escalate their privileges to that of an administrator, resulting in full site compromise. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: Improper privilege management (CWE-269) within the plugin’s account/privilege handling logic.
- Trigger conditions: No authentication or user interaction is required to exploit the flaw.
- Attack vector: Network-based (remote, over HTTP), with low attack complexity.
- Impact: Successful exploitation lets an unauthenticated attacker gain administrator-level access, with high impact to confidentiality, integrity, and availability of the affected WordPress site.
Affected software
- Total Donations WordPress plugin (developed by KlbTheme) — all versions up to and including 2.0.5.
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor-supplied patched version is currently available for this issue; version 2.0.5 remains the latest known release.
- If no patch: Site owners should deactivate and remove the Total Donations plugin from affected WordPress installations until a fixed version is released. Where removal is not immediately possible, restrict access to the plugin’s endpoints and monitor for unexpected administrator account creation or privilege changes as network-level mitigations.

