CVE-2026-73391: WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability
Published Aug 19, 2026
·Updated
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Affected Software
1 affected component
WordPress Total Donations<=2.0.5
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The vulnerability is unauthenticated and remotely exploitable. An attacker does not need a WordPress account or user interaction to attempt exploitation.
2
Which installations are affected?
WordPress sites using Total Donations version 2.0.5 or earlier are affected according to the available data.
3
What is the potential impact?
Successful exploitation may allow high-impact disclosure of data and can affect resources beyond the vulnerable component. The supplied vector indicates no integrity impact and a low availability impact.