Impact
The vulnerability is an unauthenticated privilege escalation in the Total Donations plugin for WordPress. A remote attacker can exploit this flaw to gain elevated privileges within the WordPress installation, potentially allowing full control over the site, including the ability to modify or delete content, create new administrators, or install additional malware. The weakness manifests through improper authorization checks, identified as CWE-266.
Affected Systems
All installations of the Total Donations plugin by KlbTheme with versions 2.0.5 or earlier are affected. The plugin provides donation management functionality to WordPress sites and is commonly deployed by non‑technical site owners.
Risk and Exploitability
The reported CVSS score of 9.8 indicates critical severity. The EPSS score is less than 1%, indicating a very low but nonzero likelihood of exploitation, but the lack of a KEV listing suggests no currently known widespread attacks. The likely attack vector is unauthenticated access via the public web interface of the WordPress site; an attacker does not need credentials to trigger the escalation.
OpenCVE Enrichment