CVE-2014-3961: Xnau Participants Database
High severity, CVSS 7.5. EPSS: 5.6% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
Affected products
- Xnau Participants Database: up to and including 1.5.4.8; version 1.5.4 only; version 1.5.4.1 only; version 1.5.4.2 only; version 1.5.4.3 only; version 1.5.4.4 only; …
Published 2014-06-04. Last modified 2026-06-17.