CVE-2026-88802
nicheUnauthenticated Post Deletion in MDJM Event Management & Mobile Events Manager Plugins
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager plugin through 1.4.8.3 fail to check a capability, a nonce, or the type of record when processing a playlist-entry removal request, so the code permanently deletes whatever post ID the request identifies. Any unauthenticated attacker who can reach the affected site can send a crafted request to destroy arbitrary posts, pages, and media attachments, bypassing the WordPress trash so the content is unrecoverable without backups. The result is high-impact integrity loss (CVSS 3.1: 7.5, network vector, no privileges or user interaction required) but no confidentiality impact. Sites running these niche event/DJ-management plugins are affected. No public proof of concept or in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Update MDJM Event Management to version 1.7.8.5 or later and Mobile Events Manager to a version newer than 1.4.8.3, or deactivate the plugin entirely if no fixed release is available for your version line. If patching must be delayed, use a WAF or firewall rule to block unauthenticated requests to the plugin's playlist-entry-removal AJAX/action endpoint. Because deletion bypasses the trash, verify working backups and audit the site for unexplained missing posts, pages, or media attachments.
| MDJM Event Management (WordPress plugin) | before 1.7.8.5 |
| Mobile Events Manager (WordPress plugin) | through 1.4.8.3 (<= 1.4.8.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.