Junglewise Threat Intelligence

CVE-2026-59525: Roland Barker Participants Database SQL injection

CVE-2026-59525 · Severity: critical · CVSS 9.3 · Published 2026-07-23

Technologies: Roland Barker (xnau webdesign) Participants Database. Vendors: Xnau Webdesign.

Executive brief

Participants Database is a WordPress plugin used to manage and display lists of people or records. A critical security flaw allows attackers to interact directly with the website's database without needing a password. This could lead to the theft of sensitive user information or disruption of the website's operations.

Technical details

A SQL injection vulnerability exists in the Participants Database plugin for WordPress (versions <= 2.7.8.3) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is exploitable by unauthenticated remote attackers over the network without any user interaction. By sending specially crafted requests, an attacker can bypass security controls to execute arbitrary SQL queries against the backend database. This can result in the unauthorized extraction of sensitive data or partial impact on database availability. The issue is resolved in version 2.7.8.4.

Affected products

  • Roland Barker (xnau webdesign) Participants Database <= 2.7.8.3

Timeline

  • 2026-06-03: other: Vulnerability reported by researcher L4m
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset
  • 2026-07-23: patched: Fix available in version 2.7.8.4

References

Related threats