๐Ÿ” CVE Alert

CVE-2026-88802

HIGH 7.5

MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

Vendor unknown
Product mdjm event management
Published Sep 13, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for unknown mdjm event management

Be the first to know when new high vulnerabilities affecting unknown mdjm event management are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / MDJM Event Management
0 < 1.7.8.5
Unknown / Mobile Events Manager
0 โ‰ค 1.4.8.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/cac1846c-bbf4-4ad2-8dfb-d7025034a9a7/

Credits

Enrico Marcolini (Dottor Marc) Claudio Marchesini (Dottor Marc) WPScan