Description
WordPress Plugin Total Donations for Wordpress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access sensitive data, make unauthorized changes to the site's content and configuration, or take over the vulnerable site. WordPress Plugin Total Donations for Wordpress version 2.0.5 is vulnerable; prior versions may also be affected.
Remediation
DELETE the plugin
References
Related Vulnerabilities
phpList Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-3188)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46816)
WordPress Plugin Limit Login Attempts Reloaded Cross-Site Scripting (2.7.0)