CVE-2026-94159: WordPress Total Donations plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Total Donations totaldonations allows Stored XSS.This issue affects Total Donations: from n/a through 2.0.5.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The available data indicates network-reachable exploitation with low attack complexity and no required privileges, but user interaction is required. The vulnerability is a stored XSS issue, so injected content may execute when another user views the affected page or content.
Which versions are affected?
Total Donations versions through 2.0.5 are affected. The lower bound is unspecified in the available data.
What impact can exploitation have?
The supplied CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. Stored script execution can occur in a different security context when a user interacts with affected content.