CVE-2026-78570
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-78570 is a critical Privilege Escalation vulnerability in the Total Donations plugin for WordPress, affecting all versions up to and including 2.0.5. It allows unauthenticated remote attackers to elevate their privileges to administrator level without any user interaction. The vulnerability was published on August 25, 2026, and is classified under CWE-269 (Improper Privilege Management). It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Patchstack).

Technical details

The root cause is classified as CWE-269 (Improper Privilege Management), meaning the plugin fails to properly assign, verify, or restrict privilege levels for actors interacting with its functionality. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The specific mechanism by which privilege escalation is achieved has not been publicly detailed in available sources, but the vulnerability is attributed to researcher Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, who reported it on February 6, 2026 (Patchstack). No public proof-of-concept exploit code has been identified at this time (GitHub Advisory).

Impact

Successful exploitation grants an unauthenticated attacker full administrator access to the affected WordPress installation, enabling complete site compromise. With administrator privileges, an attacker can install malicious plugins or themes, exfiltrate sensitive user and site data, deface the website, establish persistent backdoors, or use the compromised site as a launchpad for further attacks against site visitors or connected infrastructure. All three security pillars — confidentiality, integrity, and availability — are rated as High impact (GitHub Advisory, Patchstack).

Exploitability

As of the disclosure date (August 25, 2026), there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported as 0.0, indicating low current exploitation probability, though Patchstack notes that vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity (Patchstack). No threat actor attribution or CISA KEV catalog listing has been identified for this CVE. The combination of no authentication requirement and network accessibility makes this a high-priority target for opportunistic attackers.

Mitigation and workarounds

As of the disclosure date, no official patch from the plugin developer has been released for the Total Donations plugin beyond version 2.0.5 (Patchstack). Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available. Site administrators should immediately disable or remove the Total Donations plugin if running version 2.0.5 or earlier, and monitor for any unauthorized administrator account creation. Consulting the GitHub Advisory at GHSA-jc8r-vc53-6jvv for updated patch availability is recommended (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, with the disclosure coordinated through Patchstack and assigned by Wordfence (Patchstack). Patchstack classified it as high priority and noted it is the type of vulnerability commonly leveraged in mass-exploit campaigns against WordPress sites. Early social media activity was observed on Mastodon (infosec.exchange) shortly after disclosure, and the vulnerability was indexed by multiple security aggregators including VulDB and Radar by Offseq (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management