{"id":"CVE-2026-13596","title":"The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.","summary":"The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13596","references":[{"url":"https://wpscan.com/vulnerability/e22227c8-506e-4188-a7a1-1952b41c47f5/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00262,"epssPercentile":0.18342,"ingestedAt":"2026-08-02T01:16:32.413Z","slug":"CVE-2026-13596","body":"## Overview\n\nThe Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}