ZeroHour

CVE-2026-88802

niche

Unauthenticated Post Deletion in MDJM Event Management & Mobile Events Manager Plugins

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager plugin through 1.4.8.3 fail to check a capability, a nonce, or the type of record when processing a playlist-entry removal request, so the code permanently deletes whatever post ID the request identifies. Any unauthenticated attacker who can reach the affected site can send a crafted request to destroy arbitrary posts, pages, and media attachments, bypassing the WordPress trash so the content is unrecoverable without backups. The result is high-impact integrity loss (CVSS 3.1: 7.5, network vector, no privileges or user interaction required) but no confidentiality impact. Sites running these niche event/DJ-management plugins are affected. No public proof of concept or in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update MDJM Event Management to version 1.7.8.5 or later and Mobile Events Manager to a version newer than 1.4.8.3, or deactivate the plugin entirely if no fixed release is available for your version line. If patching must be delayed, use a WAF or firewall rule to block unauthenticated requests to the plugin's playlist-entry-removal AJAX/action endpoint. Because deletion bypasses the trash, verify working backups and audit the site for unexplained missing posts, pages, or media attachments.

Affected
MDJM Event Management (WordPress plugin)before 1.7.8.5
Mobile Events Manager (WordPress plugin)through 1.4.8.3 (<= 1.4.8.3)
Estimated exposure
nichelikely on the order of a few thousand sites or fewer (low thousands at most) — Both are niche event/DJ-management plugins available on WordPress.org with historically small active-install bases; no install counts were provided in the data, so this is a clearly uncertain order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.