Impact
An unauthenticated SQL injection flaw exists in WordPress Participants Database plugin versions up to and including 2.7.8.3. The vulnerability allows an attacker to supply malicious input that is incorporated into database queries without proper sanitization, leading to unauthorized read, modification or deletion of participant data. This flaw is classified as CWE-89.
Affected Systems
WordPress sites running Roland Barker’s Participants Database plugin with version 2.7.8.3 or earlier are affected. The plugin is distributed through the official WordPress plugin repository, and sites that have not applied the latest release are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, yet the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw can be triggered by sending crafted requests to exposed plugin endpoints; no special privileges are required on the server. If a vulnerable site is publicly reachable, the risk remains significant, and attackers could potentially exfiltrate sensitive data or alter the database.
OpenCVE Enrichment