CVE-2026-13596
Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
| Vendor | unknown |
| Product | participants database |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown participants database
Be the first to know when new unknown vulnerabilities affecting unknown participants database are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Participants Database
0 < 2.7.8.4
References
Credits
Joรฃo Ramos Maciel WPScan