CVE-2026-88802: MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: MDJM Event Managementto a version that resolves this vulnerability.Fixed in 1.7.8.5 - Upgrade
Upgrade
WordPress plugin: Mobile Events Managerto a version that resolves this vulnerability.Fixed in 1.4.8.3
Event History
Frequently Asked Questions
Which plugin versions need remediation?
MDJM Event Management versions before 1.7.8.5 are affected. Mobile Events Manager versions through 1.4.8.3 are affected.
Can this be exploited without a WordPress account or user interaction?
Yes. The issue can be exploited by unauthenticated attackers and requires neither privileges nor user interaction.