MDJM Event Management vulnerability

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

Published 13 Sep 2026Updated 13 Sep 20261 sources
CVSS 7.5

Source timeline

CVE record published by NVDView source ↗