CVE Tools

Description

Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

In plain language

AI Worth attention

CVE-2019-6703 is a WordPress plugin flaw (Calmar Webmedia “Total Donations” up to version 2.0.5) that lets outsiders change your site settings without logging in, so you should act if you use this plugin.

Executive summary

CVE-2019-6703 is an access-control failure in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin (through 2.0.5) that allows unauthenticated attackers to call an admin-ajax action (miglaA_update_me) to update arbitrary WordPress option values, enabling site takeover by changing user/role-related settings.

If affected, business impact
Full site takeoverAdministrator user access gainedLoss of control over donations pagesPotential customer data exposure

What to do now

  1. Check whether you run the WordPress plugin “Total Donations” and identify its version (especially if it’s 2.0.5 or older).
  2. If the plugin is installed and version is 2.0.5 or older, immediately disable the “Total Donations” plugin in WordPress.
  3. Look for any vendor update for “Total Donations” that addresses CVE-2019-6703; if you cannot find a fixed version, plan to remove the plugin and replace it with a safe alternative.
  4. Restrict or temporarily block access to WordPress’s admin-ajax.php from the internet at your firewall/WAF while you remediate.
  5. After changes, verify no new administrator accounts were created and review WordPress user roles and recent admin activity.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2019-6703 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows