Total Donations [total-donations] <= 3.0.8 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations allows Reflected XSS.This issue affects Total Donations: from n/a through 3.0.8.
- Affected:
- up to 3.0.8
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-43837 on NVD →
Total Donations <= 3.0.8 - Unauthenticated Stored Cross-Site Scripting
high
The Total Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user ac...
- CVSS:
- 7.2
- Affected:
- up to 3.0.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2025
CVE-2025-43837 on NVD →
Total Donations [total-donations] < 3.0.0 (closed)
unknown
[en] Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_upda...
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 27, 2019
CVE-2019-6703 on NVD →
Total Donations <= 2.0.5 - Missing Authorization to Arbitrary Options Update
critical
Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me...
- CVSS:
- 9.8
- Affected:
- up to 2.0.5
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 25, 2019
CVE-2019-6703 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database