SQL Injection Vulnerability in Participants Database Plugin for WordPress
CVE-2026-13596
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 August 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-13596?
The Participants Database plugin for WordPress versions prior to 2.7.8.4 is susceptible to SQL injection due to insufficient sanitization and escaping of user-supplied parameters. This flaw enables attackers without authentication to execute arbitrary SQL queries, potentially compromising the database integrity and gaining unauthorized access to sensitive information.
Affected Version(s)
Participants Database 0 < 2.7.8.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.