The Total Donations plugin for WordPress contains a critical privilege escalation vulnerability affecting all versions up to and including 2.0.5. Unauthenticated attackers can exploit this flaw to elevate their privileges to administrator level without any prior authentication. The vulnerability has been assigned CVE-2026-78570 and is documented by both NVD/NIST and security researchers at Patchstack and Wordfence. No patch details are explicitly mentioned, but the affected version ceiling is 2.0.5. The ability for unauthenticated users to gain admin access makes this a high-severity issue for any WordPress site running the affected plugin. Site administrators should immediately assess their exposure and apply any available updates or mitigations.