What is CVE-2026-11354?
A critical vulnerability (CVE-2026-11354) has been discovered in the Participants Database plugin for WordPress. All versions up to and including 2.7.8.3 are affected via the 'id' parameter, allowing unauthenticated attackers to overwrite arbitrary participant records by numeric ID. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: WordPress üçün Participants Database pluginində kritik həssaslıq aşkarlanıb (CVE-2026-11354). 2.7.8.3 versiyasına qədər olan bütün versiyalar 'id' parametri vasitəsilə təsirlənir və autentifikasiya olunmamış hücumçulara ixtiyari iştirakçı qeydlərini rəqəmli ID ilə üzərinə yazmağa imkan verir. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which WordPress plugin is affected by CVE-2026-11354 and what causes the vulnerability?
The vulnerability affects the Participants Database plugin and is caused via the 'id' parameter, allowing unauthenticated attackers to overwrite arbitrary participant records by numeric ID.
What measure should be taken to protect against CVE-2026-11354?
Updating the Participants Database plugin to the latest version is recommended, as all versions up to and including 2.7.8.3 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.