Unauthenticated Arbitrary File Deletion in Participants Database Plugin by WordPress
CVE-2026-59555
10CRITICAL
What is CVE-2026-59555?
The Participants Database plugin for WordPress versions up to 2.7.8.3 has a vulnerability that permits unauthenticated users to delete arbitrary files on the server. This flaw can lead to loss of important data or functionality within the website, presenting a significant security risk.
Affected Version(s)
Participants Database <= 2.7.8.3