Impact
Unauthenticated arbitrary file deletion affects WordPress Participants Database Plugin versions 2.7.8.3 and earlier. The flaw allows an attacker to delete any file on the web server that the WordPress process can access, leading to data loss, service disruption, or sabotage of the site.
Affected Systems
Roland Barker’s Participants Database plugin for WordPress is impacted, specifically any installation running version 2.7.8.3 or older.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity. Although the EPSS score is below 1 percent, indicating low current exploitation probability, the description indicates unauthenticated access, and based on the nature of the vulnerability it is inferred that an attacker could send crafted HTTP requests that trigger the deletion logic. The flaw is not listed in CISA’s KEV catalog, and the lack of a current EPSS spike does not reduce the critical need for remediation.
OpenCVE Enrichment