Title: Security vulnerability reported
Last modified: July 28, 2026

---

# Security vulnerability reported

 *  [brightgirl](https://wordpress.org/support/users/brightgirl/)
 * (@brightgirl)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-reported-4/)
 * Hi – I realize Patchstack is calling this a low impact vulnerability and unlikely
   to be exploited, but still wanted to make sure you are aware so it can be addressed
   in the next update. Is there an ETA for a fix?
   [https://patchstack.com/database/wordpress/plugin/participants-database/vulnerability/wordpress-participants-database-plugin-2-7-8-4-broken-access-control-vulnerability](https://patchstack.com/database/wordpress/plugin/participants-database/vulnerability/wordpress-participants-database-plugin-2-7-8-4-broken-access-control-vulnerability)
   Karen

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Author [rolandbarker](https://wordpress.org/support/users/rolandbarker/)
 * (@rolandbarker)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-reported-4/#post-18977838)
 * This was fixed in version 2.7.8.2 several months ago. Patchstack has been a bit
   slow validating the patch. You can see the fix in PDb_Base::delete_file() where
   the path to the file to be deleted is provided by the plugin, not by the user.
 *  Plugin Author [rolandbarker](https://wordpress.org/support/users/rolandbarker/)
 * (@rolandbarker)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-reported-4/#post-18977839)
 * Update: this is a new report, so I’m looking into it now.
 * By the way, we don’t publicize these unless I don’t fix it, this was scheduled
   to be published on August 27 if I don’t fix it before that.

Viewing 2 replies - 1 through 2 (of 2 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsecurity-vulnerability-reported-4%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/participants-database/assets/icon-256x256.jpg?rev=1389807)
 * [Participants Database](https://wordpress.org/plugins/participants-database/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/participants-database/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/participants-database/)
 * [Active Topics](https://wordpress.org/support/plugin/participants-database/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/participants-database/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/participants-database/reviews/)

 * 2 replies
 * 2 participants
 * Last reply from: [rolandbarker](https://wordpress.org/support/users/rolandbarker/)
 * Last activity: [1 week, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-reported-4/#post-18977839)
 * Status: not resolved