What is CVE-2026-13596?
In the Participants Database WordPress plugin versions before 2.7.8.4, a user-supplied parameter is not properly sanitized and escaped before being used in a SQL query. This vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially compromising the site's database. Updating the plugin to the latest version is recommended.
Azərbaycanca: Participants Database WordPress plugin-in 2.7.8.4 versiyasından əvvəlki versiyalarında istifadəçi tərəfindən təqdim olunan parametr düzgün təmizlənmədiyi üçün SQL sorğularında istifadə olunur. Bu zəiflik autentifikasiya olunmamış hücumçulara SQL injection hücumları həyata keçirməyə imkan verir, saytın verilənlər bazasını ələ keçirmək riski yaradır. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What security issue exists in older versions of the Participants Database plugin?
There is an SQL injection vulnerability in versions of the plugin before 2.7.8.4. A user-supplied parameter is not properly sanitized, allowing unauthenticated attackers to manipulate SQL queries.
How can I protect my site from this SQL injection vulnerability?
It is recommended to update the Participants Database plugin to the latest version to eliminate the risk of database compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.