← Voltar à pesquisa de CVEs

CVE-2026-11354

Participants Database

Descrição

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the -id- parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim-s stored personally identifiable information including names, email addresses, phone numbers, and any other fields collected in the participant database. An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then delivers the private-access link to the attacker-controlled mailbox.

CVSS 5.3EPSS 0.23900000000000002%Risco 0.54
Ver fonte
Publicação
2026-07-24 04:16:51
Versões afetadas
<=2.7.8.3
Tipo
Biblioteca
Última alteração
2026-07-24 22:16:50
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N