Description
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Published: 2026-07-23
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated arbitrary file deletion affects WordPress Participants Database Plugin versions 2.7.8.3 and earlier. The flaw allows an attacker to delete any file on the web server that the WordPress process can access, leading to data loss, service disruption, or sabotage of the site.

Affected Systems

Roland Barker’s Participants Database plugin for WordPress is impacted, specifically any installation running version 2.7.8.3 or older.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity. Although the EPSS score is below 1 percent, indicating low current exploitation probability, the description indicates unauthenticated access, and based on the nature of the vulnerability it is inferred that an attacker could send crafted HTTP requests that trigger the deletion logic. The flaw is not listed in CISA’s KEV catalog, and the lack of a current EPSS spike does not reduce the critical need for remediation.

Generated by OpenCVE AI on August 3, 2026 at 22:17 UTC.

Remediation

Vendor Solution

Update the WordPress Participants Database Plugin to the latest available version (at least 2.7.8.4).


OpenCVE Recommended Actions

  • Update the WordPress Participants Database Plugin to version 2.7.8.4 or later.
  • Disable or restrict file deletion permissions for the plugin directory, ensuring the WordPress process can only read and not delete arbitrary files.
  • Monitor server logs for unusual deletion activity and apply Web Application Firewall rules to block crafted HTTP requests targeting the deletion endpoint.

Generated by OpenCVE AI on August 3, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Rolandbarkerxnauwebdesign
Rolandbarkerxnauwebdesign participants Database
Wordpress
Wordpress wordpress
Vendors & Products Rolandbarkerxnauwebdesign
Rolandbarkerxnauwebdesign participants Database
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Title WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Rolandbarkerxnauwebdesign Participants Database
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T16:05:31.206Z

Reserved: 2026-07-05T21:28:04.587Z

Link: CVE-2026-59555

cve-icon Vulnrichment

Updated: 2026-07-23T16:05:22.379Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:33.803

Modified: 2026-07-23T16:17:30.057

Link: CVE-2026-59555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')