SQL Injection
3 records23.1%First: 2014. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 13 vulnerability records associated with Participants Database, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2017 | 1 | |
| 2020 | 1 | |
| 2023 | 4 | |
| 2024 | 1 | |
| 2025 | 1 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 15.4% |
| High | 3 | 23.1% |
| Medium | 8 | 61.5% |
First: 2014. Latest: 2026.
First: 2017. Latest: 2025.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.7.8.42.7.72.5.9.32.5.62.5.02.52.4.61.9.5.61.7.5.101.5.4.9Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.7.8.3 | Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter | July 23, 2026 | 2.7.8.4 | Medium |
*-2.7.8.4 | Participants Database <= 2.7.8.4 - Missing Authorization | July 22, 2026 | Not supplied | Medium |
*-2.7.8.3 | Participants Database <= 2.7.8.3 - Unauthenticated Arbitrary File Deletion | July 22, 2026 | 2.7.8.4 | Critical |
*-2.7.8.3 | Participants Database <= 2.7.8.3 - Unauthenticated SQL Injection | July 22, 2026 | 2.7.8.4 | High |
*-2.7.6.3 | Participants Database <= 2.7.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | September 22, 2025 | 2.7.7 | Medium |
*-2.5.9.2 | Participants Database <= 2.5.9.2 - Unauthenticated PHP Object Injection | August 7, 2024 | 2.5.9.3 | High |
*-2.5.5 | Participants Database <= 2.5.5 - Missing Authorization | November 27, 2023 | 2.5.6 | Medium |
*-2.4.9 | Participants Database <= 2.4.9 - Cross-Site Request Forgery via _process_general | May 3, 2023 | 2.5.0 | Medium |
[*, 2.5) | Participants Database <= 2.4.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings | May 3, 2023 | 2.5 | Medium |
*-2.4.5 | Participants Database <= 2.4.5 - Cross Site Request Forgery | January 20, 2023 | 2.4.6 | Medium |
[*, 1.9.5.6) | Participants Database <= 1.9.5.5 - SQL Injection | February 10, 2020 | 1.9.5.6 | High |
*-1.7.5.9 | Participants Database <= 1.7.5.9 - Unauthorized Cross-Site Scripting | September 6, 2017 | 1.7.5.10 | Medium |
[*, 1.5.4.9) | Participants Database < 1.5.4.9 - SQL Injection | June 2, 2014 | 1.5.4.9 | Critical |
Selected source records
Published: July 23, 2026
Published: July 22, 2026
Published: July 22, 2026
Published: July 22, 2026
Published: September 22, 2025
Published: August 7, 2024
Published: November 27, 2023
Published: May 3, 2023
Published: June 2, 2014
Published: July 22, 2026
Published: August 7, 2024
Published: July 22, 2026
Published: February 10, 2020
Published: September 22, 2025
Published: September 6, 2017
Published: May 3, 2023
Published: July 22, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.