WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Participants Database

Build and maintain a fully customizable database of participants, members or anything with signup forms, admin backend, custom lists, and CSV support.

15Reported vulnerabilities
9.1Highest CVSS score
2.7.8.5Latest version
7,000+Active installs

What to do now

Update Participants Database to 2.7.8.5 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 31, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2014-3961 High 7.5 5.6% 1.5.4.8 and earlier
1.5.4 to 1.5.4 (inclusive)
1.5.4.1 to 1.5.4.1 (inclusive)
1.5.4.2 to 1.5.4.2 (inclusive)
1.5.4.3 to 1.5.4.3 (inclusive)
1.5.4.4 to 1.5.4.4 (inclusive)
1.5.4.5 to 1.5.4.5 (inclusive)
1.5.4.6 to 1.5.4.6 (inclusive)
1.5.4.7 to 1.5.4.7 (inclusive)
1.5.4.9 June 4, 2014
CVE-2026-59555 Critical 9.1 0.6% 2.7.8.3 and earlier 2.7.8.4 July 22, 2026
CVE-2026-28189 Critical 9.1 0.3% 2.7.8.4 and earlier 2.7.8.5 August 13, 2026
CVE-2024-43141 High 8.1 0.6% 2.5.9.2 and earlier 2.5.9.3 August 7, 2024
CVE-2020-8596 High 7.5 1.6% 1.9.5.5 and earlier 1.9.5.6 February 11, 2020
CVE-2026-13596 High 7.5 0.3% Before 2.7.8.4 2.7.8.4 August 5, 2026
CVE-2026-59525 High 7.5 0.4% 2.7.8.3 and earlier 2.7.8.4 July 22, 2026
CVE-2017-14126 Medium 6.1 2.3% 1.7.5.10 to 1.7.5.10 (inclusive) 1.7.5.10 September 4, 2017
CVE-2025-58008 Medium 6.4 0.2% 2.7.6.3 and earlier 2.7.7 September 22, 2025
CVE-2023-31235 Medium 5.4 0.3% 2.4.9 and earlier 2.5.0 May 3, 2023
CVE-2026-11354 Medium 5.3 0.3% 0 to 2.7.8.3 (inclusive) 2.7.8.4 July 24, 2026
CVE-2023-48751 Medium 5.3 0.3% 2.5.5 and earlier 2.5.6 November 27, 2023
CVE-2026-27423 Medium 4.3 0.3% 2.7.8.4 and earlier 2.7.8.5 July 22, 2026
WF-a52015fe-c4df-46a6-8f23-b33730797f4c Medium 4.4 Before 2.5 2.5 May 3, 2023
CVE-2022-47612 Medium 4.3 0.2% 2.4.5 and earlier 2.4.6 January 20, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.