CVE-2026-11354
Received Received - Intake

Participants Database Plugin Sensitive Information Exposure

Vulnerability report for CVE-2026-11354, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Wordfence

Description

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's stored personally identifiable information including names, email addresses, phone numbers, and any other fields collected in the participant database. An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then delivers the private-access link to the attacker-controlled mailbox.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
participants_database plugin to 2.7.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Participants Database plugin for WordPress has a flaw where unauthenticated attackers can access and modify sensitive participant data. By exploiting the 'id' parameter, attackers can overwrite records and redirect access links to their own email, gaining full read and edit access to personally identifiable information like names, emails, and phone numbers.

Detection Guidance

Check WordPress sites using the Participants Database plugin for versions up to 2.7.8.3. Look for unauthorized modifications to participant records or unexpected email redirections. Review server logs for GET requests to pages with public signup or record forms followed by POST requests with action=update and arbitrary id values.

Impact Analysis

If you use this plugin, attackers could steal or alter your stored participant data, leading to privacy breaches, identity theft, or misuse of personal information. Unauthorized access could also disrupt your database operations.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personally identifiable information. GDPR requires protecting personal data, and HIPAA mandates safeguarding health-related data. A breach could result in legal penalties and loss of compliance certifications.

Mitigation Strategies

Update the Participants Database plugin to the latest version beyond 2.7.8.3. If an update is unavailable, consider disabling the plugin temporarily. Monitor participant records for unauthorized changes and review access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11354. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart