Junglewise Threat Intelligence

CVE-2026-7537: MDJM Event Management arbitrary file upload in mdjm_send_comm_email

CVE-2026-7537 · Severity: high · CVSS 7.2 · Published 2026-06-06

Technologies: MDJM Event Management. Vendors: MDJM.

Executive brief

The MDJM Event Management plugin for WordPress, used for managing mobile DJ bookings and communications, contains a security flaw in its email attachment feature. This vulnerability allows an authorized administrator to upload malicious files, such as web shells, directly to the web server. If exploited, an attacker could take full control of the website, potentially leading to data theft, site defacement, or the installation of further malware.

Technical details

An arbitrary file upload vulnerability exists in the MDJM Event Management plugin for WordPress due to a lack of file type, extension, or MIME type validation in the mdjm_send_comm_email() function. The vulnerability is located in 'includes/admin/communications/comms-functions.php' where user-supplied files from the 'mdjm_email_upload_file' parameter are passed directly to move_uploaded_file() without sanitization. An authenticated attacker with administrator-level privileges (or the 'mdjm_comms_send' capability) can upload executable PHP files to the WordPress uploads directory. This can be leveraged to achieve remote code execution (RCE) on the underlying server. A patch was introduced in version 1.7.8.4 to address this issue.

Affected products

  • MDJM MDJM Event Management (mobile-dj-manager) up to, and including, 1.7.8.3

Timeline

  • 2026-06-06: advisory: NVD publication date
  • 2026-06-06: disclosed: Public disclosure of vulnerability and PoC

References

Related threats