Impact
The vulnerability allows an unauthenticated attacker to delete arbitrary files on the server hosting a WordPress site that uses the Participants Database plugin. By sending a crafted HTTP request, the attacker can remove critical files, potentially disrupting website functionality or deleting sensitive data. The flaw falls under input path traversal (CWE-22) and compromises the integrity and availability of the affected platform.
Affected Systems
WordPress participants Database plugin, vendor Roland Barker, versions up to and including 2.7.8.4 are vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. The EPSS score is not provided but the vulnerability is unauthenticated, meaning any user of the site’s front‑end can trigger the deletion by accessing the problematic endpoint. The issue is not currently listed in the CISA KEV catalog. The attack vector is remote and does not require prior authentication; an attacker can simply send the request to the vulnerable plugin’s file deletion endpoint.
OpenCVE Enrichment