{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/klbtheme/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-78568"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Total Donations"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["KlbTheme"],"content_html":"\u003cp\u003eThe Total Donations plugin for WordPress (up to and including version 2.0.5) contains a critical SQL injection vulnerability identified as CVE-2026-78568. The flaw exists due to insufficient input validation and a lack of parameterized queries when handling user-supplied parameters. This security deficiency allows unauthenticated remote attackers to append arbitrary SQL commands to existing database queries. Successful exploitation permits an attacker to perform unauthorized operations on the backend database, such as exfiltrating sensitive data, modifying application content, or disrupting service availability. Given the plugin's function, it is likely to be targeted for the extraction of donor or administrative information.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target WordPress site utilizing the Total Donations plugin version 2.0.5 or earlier.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP GET or POST request containing a malicious SQL payload targeted at an exposed parameter within the plugin's input fields.\u003c/li\u003e\n\u003cli\u003eThe request is transmitted to the web server hosting the vulnerable WordPress instance.\u003c/li\u003e\n\u003cli\u003eThe web application's input processing logic fails to properly sanitize or escape the attacker-supplied parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin concatenates the malicious input directly into a database query string.\u003c/li\u003e\n\u003cli\u003eThe database engine executes the concatenated query, allowing the injected SQL commands to run with the privileges of the database user.\u003c/li\u003e\n\u003cli\u003eThe attacker iterates through database tables to exfiltrate sensitive data via boolean-based or union-based injection techniques.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-78568 can lead to the complete compromise of the site's database. This includes the potential theft of sensitive user data, donor information, and site configuration details. Given the critical CVSS score of 9.8, exploitation is unauthenticated and requires no user interaction, making it highly attractive for automated botnets scanning the web for vulnerable WordPress plugins.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Total Donations plugin to the latest available version beyond 2.0.5 immediately to remediate CVE-2026-78568.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately available, disable the plugin or restrict access to the affected web paths at the WAF level.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests containing common SQL injection characters (such as single quotes, semicolons, and comment indicators) targeting plugin-specific paths.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect anomalous SQL injection patterns in web server logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T10:07:20Z","date_published":"2026-08-25T10:07:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-total-donations-sqli/","summary":"The Total Donations plugin for WordPress versions up to 2.0.5 is vulnerable to unauthenticated SQL injection, allowing attackers to extract sensitive database information.","title":"SQL Injection Vulnerability in Total Donations WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-total-donations-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - KlbTheme","version":"https://jsonfeed.org/version/1.1"}