Executive brief
A critical vulnerability exists in the Participants Database plugin for WordPress, which is used to manage and display lists of people or records. An unauthenticated attacker can remotely delete any file on the web server, including critical system files or website configuration data. This can lead to a total loss of website functionality, permanent data loss, or the bypass of security controls if configuration files are removed.
Technical details
The Participants Database plugin for WordPress (versions up to and including 2.7.8.3) is vulnerable to unauthenticated arbitrary file deletion. This issue stems from improper limitation of a pathname to a restricted directory (CWE-22), commonly known as path traversal. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to delete sensitive files on the server, such as wp-config.php or .htaccess. Successful exploitation can lead to a complete denial of service or allow the attacker to reset the site and gain administrative control. The vulnerability is patched in version 2.7.8.4.
Affected products
- Roland Barker (xnau webdesign) Participants Database <= 2.7.8.3
Timeline
- 2026-04-24: other: Reported by researcher hhhai
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD
- 2026-07-23: patched: Fixed in version 2.7.8.4