CVE-2026-59555: WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability
Published Jul 23, 2026
·Updated
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Affected Software
1 affected component
WordPress Participants Database Plugin<=2.7.8.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Participants Database Pluginto a version that resolves this vulnerability.Fixed in 2.7.8.4
Event History
Jul 23, 2026
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59555?
The severity of CVE-2026-59555 is rated as critical with a score of 10.
2
What does CVE-2026-59555 affect?
CVE-2026-59555 affects versions of the WordPress Participants Database plugin up to 2.7.8.3.
3
How do I fix CVE-2026-59555?
To fix CVE-2026-59555, upgrade the WordPress Participants Database plugin to a version later than 2.7.8.3.
4
What kind of vulnerability is CVE-2026-59555?
CVE-2026-59555 is an unauthenticated arbitrary file deletion vulnerability due to path traversal.
5
Can CVE-2026-59555 be exploited remotely?
Yes, CVE-2026-59555 can be exploited remotely due to its unauthenticated nature.