Vendorsxnauparticipants_databaseall versions
Vulnerabilities

xnau Participants Database

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-31235
WordPress Participants Database Plugin <= 2.4.9 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-09 · Modified
8.8EPSS 0.003
CVE-2023-48751
WordPress Participants Database Plugin <= 2.5.5 is vulnerable to Broken Access Control
Published 2023-12-18 · Modified
8.8EPSS 0.003
CVE-2014-3961
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
Published 2014-06-04 · Modified
7.51 PoCEPSS 0.056
CVE-2020-8596
participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).
Published 2020-02-10 · Modified
7.5EPSS 0.016
CVE-2017-14126
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
Published 2017-09-04 · Modified
6.11 PoCEPSS 0.023
CVE-2022-47612
WordPress Participants Database Plugin <= 2.4.5 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-02-28 · Modified
4.3EPSS 0.002