CVE-2026-59525: WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability
Published Jul 23, 2026
·Updated
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
Affected Software
1 affected component
WordPress Participants Database<=2.7.8.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Participants Database pluginto a version that resolves this vulnerability.Fixed in 2.7.8.4
Event History
Jul 23, 2026
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59525?
CVE-2026-59525 has a critical severity rating of 9.3.
2
How do I fix CVE-2026-59525?
To fix CVE-2026-59525, update the Participants Database plugin to version 2.7.8.4 or later.
3
What type of vulnerability is CVE-2026-59525?
CVE-2026-59525 is an unauthenticated SQL Injection vulnerability.
4
Which versions of the software are affected by CVE-2026-59525?
CVE-2026-59525 affects the WordPress Participants Database plugin versions up to and including 2.7.8.3.
5
What are the potential impacts of CVE-2026-59525?
CVE-2026-59525 may allow attackers to execute arbitrary SQL commands, potentially leading to data exposure.