CVE-2014-3961
Summary
| CVE | CVE-2014-3961 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-04 14:55:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xnau | Participants Database | 1.5.4 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.1 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.2 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.3 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.4 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.5 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.6 | All | All | All |
| Application | Xnau | Participants Database | 1.5.4.7 | All | All | All |
| Application | Xnau | Participants Database | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress Participants Database 1.5.4.8 SQL Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| osvdb.org/show/osvdb/107626 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| WordPress › Participants Database « WordPress Plugins | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Patch |
| www.yarubo.com/advisories/1 | af854a3a-2127-422b-91ae-364da2661108 | www.yarubo.com | Exploit, URL Repurposed |
| Wordpress Participants Database 1.5.4.8 - SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| WordPress Participants Database Plugin SQL Injection and Access Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Full Disclosure: Yarubo #1: Arbitrary SQL Execution in Participants Database for Wordpress | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.