plugin

Total Donations Vulnerabilities

4 known security issues reported for the Total Donations WordPress plugin. Most recent disclosed May 19, 2025.

1 critical 1 high

Running Total Donations on your site? Check whether your installed version is affected.

Scan your site free

Total Donations [total-donations] <= 3.0.8 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations allows Reflected XSS.This issue affects Total Donations: from n/a through 3.0.8.

Affected:
up to 3.0.8
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-43837 on NVD →

Total Donations <= 3.0.8 - Unauthenticated Stored Cross-Site Scripting

high

The Total Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user ac...

CVSS:
7.2
Affected:
up to 3.0.8
Fix:
No patched version reported
Disclosed:
Apr 29, 2025

CVE-2025-43837 on NVD →

Total Donations [total-donations] < 3.0.0 (closed)

unknown

[en] Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_upda...

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Jan 27, 2019

CVE-2019-6703 on NVD →

Total Donations <= 2.0.5 - Missing Authorization to Arbitrary Options Update

critical

Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me...

CVSS:
9.8
Affected:
up to 2.0.5
Fixed in:
3.0.0
Disclosed:
Jan 25, 2019

CVE-2019-6703 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database