Participants Database <= 2.7.8.4 - Unauthenticated Arbitrary File Deletion
critical
The Participants Database plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.7.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution whe...
- CVSS:
- 9.1
- Affected:
- up to 2.7.8.4
- Fixed in:
- 2.7.8.5
- Disclosed:
- Aug 13, 2026
CVE-2026-28189 on NVD →
Participants Database < 2.7.8.4 - Unauthenticated SQL Injection
high
The Participants Database plugin for WordPress is vulnerable to SQL Injection in versions up to 2.7.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr...
- CVSS:
- 7.5
- Affected:
- up to 2.7.8.4
- Fixed in:
- 2.7.8.4
- Disclosed:
- Aug 5, 2026
CVE-2026-13596 on NVD →
Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter
medium
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-ac...
- CVSS:
- 5.3
- Affected:
- up to 2.7.8.3
- Fixed in:
- 2.7.8.4
- Disclosed:
- Jul 23, 2026
CVE-2026-11354 on NVD →
Participants Database <= 2.7.8.3 - Unauthenticated Arbitrary File Deletion
critical
The Participants Database plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.7.8.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution whe...
- CVSS:
- 9.1
- Affected:
- up to 2.7.8.3
- Fixed in:
- 2.7.8.4
- Disclosed:
- Jul 22, 2026
CVE-2026-59555 on NVD →
Participants Database <= 2.7.8.3 - Unauthenticated SQL Injection
high
The Participants Database plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...
- CVSS:
- 7.5
- Affected:
- up to 2.7.8.3
- Fixed in:
- 2.7.8.4
- Disclosed:
- Jul 22, 2026
CVE-2026-59525 on NVD →
Participants Database <= 2.7.8.4 - Missing Authorization
medium
The Participants Database plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.8.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.7.8.4
- Fixed in:
- 2.7.8.5
- Disclosed:
- Jul 22, 2026
CVE-2026-27423 on NVD →
Participants Database <= 2.7.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 6.4
- Affected:
- up to 2.7.6.3
- Fixed in:
- 2.7.7
- Disclosed:
- Sep 22, 2025
CVE-2025-58008 on NVD →
Participants Database [participants-database] < 2.5.9.3 (closed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.
- Affected:
- up to 2.5.9.3
- Fixed in:
- 2.5.9.3
- Disclosed:
- Aug 13, 2024
CVE-2024-43141 on NVD →
Participants Database <= 2.5.9.2 - Unauthenticated PHP Object Injection
high
The Participants Database plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.9.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain...
- CVSS:
- 8.1
- Affected:
- up to 2.5.9.2
- Fixed in:
- 2.5.9.3
- Disclosed:
- Aug 7, 2024
CVE-2024-43141 on NVD →
Participants Database [participants-database] < 2.5.6 (closed)
unknown
[en] Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects Participants Database: from n/a through 2.5.5.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Dec 18, 2023
CVE-2023-48751 on NVD →
Participants Database <= 2.5.5 - Missing Authorization
medium
The Participants Database plugin for WordPress is vulnerable to unauthorized manipulation of data due to a missing capability check on several functions hooked via admin-post in all versions up to, and including, 2.5.5. This makes it possible for unauthenticated attackers to add and modify record fields.
- CVSS:
- 5.3
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Nov 27, 2023
CVE-2023-48751 on NVD →
Participants Database [participants-database] < 2.5.6 (closed)
unknown
The Participants Database plugin for WordPress is vulnerable to unauthorized manipulation of data due to a missing capability check on several functions hooked via admin-post in all versions up to, and including, 2.5.5. This makes it possible for unauthenticated attackers to add and modify record fields.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Nov 27, 2023
Participants Database [participants-database] < 2.5.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions.
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- Nov 9, 2023
CVE-2023-31235 on NVD →
Participants Database <= 2.4.9 - Cross-Site Request Forgery via _process_general
medium
The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.9. This is due to missing or incorrect nonce validation on the _process_general function. This makes it possible for unauthenticated attackers to process changes to lists via a forged request...
- CVSS:
- 5.4
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- May 3, 2023
CVE-2023-31235 on NVD →
Participants Database <= 2.4.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings
medium
The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- May 3, 2023
Participants Database [participants-database] < 2.5 (closed)
unknown
The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- May 3, 2023
Participants Database [participants-database] < 2.4.6 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update.
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.6
- Disclosed:
- Feb 28, 2023
CVE-2022-47612 on NVD →
Participants Database <= 2.4.5 - Cross Site Request Forgery
medium
The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.5. This is due to missing nonce validation on the process_request function. This makes it possible for unauthenticated attackers to modify participant lists via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.6
- Disclosed:
- Jan 20, 2023
CVE-2022-47612 on NVD →
Participants Database <= 1.9.5.5 - SQL Injection
high
participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).
- CVSS:
- 7.5
- Affected:
- up to 1.9.5.6
- Fixed in:
- 1.9.5.6
- Disclosed:
- Feb 10, 2020
CVE-2020-8596 on NVD →
Participants Database [participants-database] < 1.9.5.6 (closed)
unknown
[en] participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).
- Affected:
- up to 1.9.5.6
- Fixed in:
- 1.9.5.6
- Disclosed:
- Feb 10, 2020
CVE-2020-8596 on NVD →
Participants Database [participants-database] < 1.9.5.6 (closed)
unknown
Authenticated Time Based SQL Injection (SQLi) injection found by Teacish in WordPress Participants Database plugin (versions <= 1.9.5.5).
- Affected:
- up to 1.9.5.6
- Fixed in:
- 1.9.5.6
- Disclosed:
- Feb 10, 2020
Participants Database <= 1.7.5.9 - Unauthorized Cross-Site Scripting
medium
The Participants Database plugin for WordPress is vulnerable to Cross-Site Scripting via the 'Name' paremeter in versions up to, and including, 1.7.5.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.7.5.9
- Fixed in:
- 1.7.5.10
- Disclosed:
- Sep 6, 2017
CVE-2017-14126 on NVD →
Participants Database [participants-database] < 1.7.5.10 (closed)
unknown
[en] The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
- Affected:
- up to 1.7.5.10
- Fixed in:
- 1.7.5.10
- Disclosed:
- Sep 4, 2017
CVE-2017-14126 on NVD →
Participants Database [participants-database] < 1.7.5.4 (closed)
unknown
A Cross-Site Request Forgery (CSRF)/Authenticated Arbitrary File Upload Vulnerabilities in WordPress Participants Database plugin <= 1.7.5.3 can allow an attacker to upload arbitrary files. The vulnerability exsists in PDb_CSV_Import class file which doesn't check for the file type of the file. With missing a CSRF non...
- Affected:
- up to 1.7.5.4
- Fixed in:
- 1.7.5.4
- Disclosed:
- Aug 25, 2017
Participants Database [participants-database] < 1.5.4.9 (closed)
unknown
[en] SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
- Affected:
- up to 1.5.4.9
- Fixed in:
- 1.5.4.9
- Disclosed:
- Jun 4, 2014
CVE-2014-3961 on NVD →
Participants Database < 1.5.4.9 - SQL Injection
critical
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
- CVSS:
- 9.8
- Affected:
- up to 1.5.4.9
- Fixed in:
- 1.5.4.9
- Disclosed:
- Jun 2, 2014
CVE-2014-3961 on NVD →
Participants Database [participants-database] <= 2.7.6.3 (unfixed)
unknown
- Affected:
- up to 2.7.6.3
- Fix:
- No patched version reported
CVE-2025-58008 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database