CVE-2026-28189 HIGH

CVE-2026-28189: WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability

Vendor Roland Barker
Product Participants Database
Weakness CWE-22 · Path traversal
Published August 13, 2026
Last update August 13, 2026

CVSS base score

7.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Participants Database versions up to 2.7.8.4 contain a path traversal vulnerability that allows an attacker to cause a denial of service by making the site unresponsive or unavailable. The vulnerability requires user interaction—typically the victim must click a malicious link or visit a crafted page. The impact extends beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Make the site unresponsive or unavailable by triggering a denial of service condition.

Potential impact on your site

04Site Impact

Your site may become temporarily unavailable or unresponsive if a visitor is tricked into clicking a malicious link.

Conditions required to exploit

05Prerequisites

No authentication required. Victim must click a malicious link or visit an attacker-controlled page.

Key dates

06Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

08Related CVE