What this page helps you verify fast
This hub clusters every indexed record for Participants Database so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Participants Database (`participants-database`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2025-58008, CVE-2024-43141 and CVE-2023-48751, so operators can jump from disclosure to patch validation without scanning the full feed first.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
Participants Database < 1.5.4.9 - SQL Injection
Participants Database <= 2.5.9.2 - Unauthenticated PHP Object Injection
Participants Database <= 1.9.5.5 - SQL Injection
Participants Database <= 2.7.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Participants Database <= 1.7.5.9 - Unauthorized Cross-Site Scripting
Participants Database <= 2.4.9 - Cross-Site Request Forgery via _process_general
Participants Database <= 2.5.5 - Missing Authorization
Participants Database <= 2.4.5 - Cross Site Request Forgery
This hub clusters every indexed record for Participants Database so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.6.3 due to insufficient input sanitization and output escapi...
The Participants Database plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.9.2 via deserialization of untrusted input. This makes it possi...
The Participants Database plugin for WordPress is vulnerable to unauthorized manipulation of data due to a missing capability check on several functions hooked via admin-post in all versions...
Sorted by latest disclosure date so newly published issues surface first.
The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...
The Participants Database plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.9.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in...
The Participants Database plugin for WordPress is vulnerable to unauthorized manipulation of data due to a missing capability check on several functions hooked via admin-post in all versions up to, and including, 2.5.5. This makes it possible for unauthenticated attackers to add...
The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato...
The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.9. This is due to missing or incorrect nonce validation on the _process_general function. This makes it possible for unauthenticated attackers to proce...
The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.5. This is due to missing nonce validation on the process_request function. This makes it possible for unauthenticated attackers to modify participant...
The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.5. This is due to missing nonce validation on the process_request function. This makes it possible for unauthenticated attackers to modify participant...
participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if cert...
The Participants Database plugin for WordPress is vulnerable to Cross-Site Scripting via the 'Name' paremeter in versions up to, and including, 1.7.5.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts...
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.