A critical security vulnerability (CVE-2026-59555) has been disclosed in the Participants Database WordPress plugin, affecting all versions through 2.7.8.3. The flaw allows unauthenticated attackers to delete arbitrary files from vulnerable systems through a crafted request. This vulnerability carries a CVSS score of 10.0, indicating the highest severity level. Successful exploitation could lead to complete system compromise, data loss, or remote code execution through web server configuration file manipulation. The vulnerability exists due to insufficient input validation and authentication checks in file management functionality. WordPress sites utilizing the affected plugin versions are at immediate risk. Attackers require no prior authentication or user interaction to exploit this issue. Site administrators are strongly advised to upgrade to version 2.7.8.4 or later, which contains a verified fix. In the interim, implement strict web server access controls and monitor server logs for suspicious file deletion attempts. This vulnerability underscores the importance of maintaining updated plugins in WordPress environments to mitigate supply chain attack risks.
CRITICAL
CVSS 10.0
CVE-2026-59555
2026-08-13
Critical Vulnerability Allows Unauthenticated File Deletion in WordPress Plugin
A critical unauthenticated arbitrary file deletion vulnerability affects Participants Database plugin for WordPress versions 2.7.8.3 and below. Immediate patching is required to prevent remote attackers from exploiting this flaw for system compromise.