CVE-2025-58008
Participants Database
Minimum safe version
2.7.7
Update to 2.7.7 or later to address 12 fixable vulnerabilities
CVE-2024-43141
CVE-2023-48751
Participants Database <= 2.5.5 - Missing Authorization
CVE-2023-31235
Participants Database <= 2.4.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings
CVE-2022-47612
WordPress Participants Database plugin <= 1.7.5.3 - Cross-Site Request Forgery (CSRF)/Authenticated Arbitrary File Upload Vulnerabilities
WordPress Participants Database plugin <= 1.9.5.5 - Authenticated Time Based SQL Injection (SQLi) injection
CVE-2014-3961
WordPress Participants Database plugin <=1.7.5.9 - Cross-Site Scripting (XSS) vulnerability
WordPress Participants Database plugin <= 1.9.5.5 - Authenticated Time Based SQL Injection (SQLi) vulnerability