Impact
The vulnerability is a broken access control flaw in the WordPress Participants Database plugin for versions 2.7.8.4 and older. It allows an attacker to read or alter subscriber data that should be restricted. The weakness is classified as CWE‑862, indicating missing or insufficient access control. Based on the description, it is inferred that attackers must be authenticated as a subscriber or other non‑admin role to exploit this flaw, as the plugin relies on WordPress role checks for data access.
Affected Systems
WordPress installations that use the Participants Database plugin from Roland Barker are affected. Versions of the plugin up to and including 2.7.8.4 are vulnerable. Any site that has installed or kept this older version and has subscriber or similar non‑admin roles will be impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity issue, while the EPSS score of less than 1 % suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers likely need to be authenticated as a subscriber or other non‑admin role to exploit the flaw, which is inferred from the plugin behavior; the incomplete access controls could allow them to read or alter data that should be protected. The overall risk is moderate, with potential for privacy violations if an attacker obtains subscriber data.
OpenCVE Enrichment