Junglewise Threat Intelligence

CVE-2026-27423: Roland Barker Participants Database broken access control

CVE-2026-27423 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Technologies: Xnau Webdesign Participants Database. Vendors: Xnau Webdesign.

Executive brief

The Participants Database plugin for WordPress, which is used to manage and display lists of people or members, contains a security flaw in its access control mechanisms. This vulnerability allows a user with basic 'Subscriber' level permissions to perform actions they should not be authorized to do. While the impact is considered low, it could allow unauthorized modifications to database entries or settings depending on the specific functions exposed.

Technical details

A broken access control vulnerability exists in the Participants Database plugin for WordPress (versions up to and including 2.7.8.4) due to missing authorization checks (CWE-862). An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw via network requests to execute functions or modify data that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 4.3, indicating a partial impact on integrity with no impact on confidentiality or availability. As of the advisory date, no official patch has been confirmed, and users are advised to monitor for updates from the developer.

Affected products

  • Roland Barker (xnau webdesign) Participants Database <= 2.7.8.4

Timeline

  • 2025-10-24: other: Vulnerability reported by researcher Legion Hunter
  • 2026-07-22: advisory: Advisory published by Patchstack
  • 2026-07-23: disclosed: CVE published to NVD dataset

References

Related threats