The Total Donations plugin for WordPress contains a SQL Injection vulnerability affecting all versions up to and including 2.0.5. The flaw stems from insufficient escaping of user-supplied parameters and inadequate preparation of existing SQL queries. Unauthenticated attackers can exploit this vulnerability by appending additional SQL queries to extract sensitive information from the database. No authentication is required to exploit this vulnerability, making it particularly dangerous for any site running the affected plugin versions. Users are advised to update or remove the plugin to mitigate the risk of data exfiltration.