
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78570 is a critical Privilege Escalation vulnerability in the Total Donations plugin for WordPress, affecting all versions up to and including 2.0.5. It allows unauthenticated remote attackers to elevate their privileges to administrator level without any user interaction. The vulnerability was published on August 25, 2026, and is classified under CWE-269 (Improper Privilege Management). It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Patchstack).
The root cause is classified as CWE-269 (Improper Privilege Management), meaning the plugin fails to properly assign, verify, or restrict privilege levels for actors interacting with its functionality. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The specific mechanism by which privilege escalation is achieved has not been publicly detailed in available sources, but the vulnerability is attributed to researcher Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, who reported it on February 6, 2026 (Patchstack). No public proof-of-concept exploit code has been identified at this time (GitHub Advisory).
Successful exploitation grants an unauthenticated attacker full administrator access to the affected WordPress installation, enabling complete site compromise. With administrator privileges, an attacker can install malicious plugins or themes, exfiltrate sensitive user and site data, deface the website, establish persistent backdoors, or use the compromised site as a launchpad for further attacks against site visitors or connected infrastructure. All three security pillars — confidentiality, integrity, and availability — are rated as High impact (GitHub Advisory, Patchstack).
As of the disclosure date (August 25, 2026), there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported as 0.0, indicating low current exploitation probability, though Patchstack notes that vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity (Patchstack). No threat actor attribution or CISA KEV catalog listing has been identified for this CVE. The combination of no authentication requirement and network accessibility makes this a high-priority target for opportunistic attackers.
As of the disclosure date, no official patch from the plugin developer has been released for the Total Donations plugin beyond version 2.0.5 (Patchstack). Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available. Site administrators should immediately disable or remove the Total Donations plugin if running version 2.0.5 or earlier, and monitor for any unauthorized administrator account creation. Consulting the GitHub Advisory at GHSA-jc8r-vc53-6jvv for updated patch availability is recommended (GitHub Advisory).
The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, with the disclosure coordinated through Patchstack and assigned by Wordfence (Patchstack). Patchstack classified it as high priority and noted it is the type of vulnerability commonly leveraged in mass-exploit campaigns against WordPress sites. Early social media activity was observed on Mastodon (infosec.exchange) shortly after disclosure, and the vulnerability was indexed by multiple security aggregators including VulDB and Radar by Offseq (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."