Junglewise Threat Intelligence

CVE-2026-88802: MDJM Event Management unauthenticated post deletion

CVE-2026-88802 · Severity: high · CVSS 7.5 · Published 2026-09-13

Technologies: MDJM Event Management. Vendors: MDJM.

Executive brief

Two WordPress event management plugins lack proper authorization checks in their playlist entry removal functionality, allowing unauthenticated attackers to permanently delete any post, page, or media file from a WordPress site. An attacker can bypass WordPress trash/recycle features and destroy content without any authentication, leading to data loss and potential service disruption.

Technical details

The MDJM Event Management and Mobile Events Manager WordPress plugins fail to validate user capabilities, verify nonce tokens, or confirm record type before executing post deletion requests via their playlist entry removal endpoint. The vulnerability is a missing authorization check (CWE-862) that allows unauthenticated attackers to craft requests to delete arbitrary posts, pages, and media attachments. Attack vector is network-based with no authentication required or user interaction needed. An attacker can permanently destroy site content, bypassing WordPress's trash/recovery mechanism. MDJM Event Management was patched in version 1.7.8.5; Mobile Events Manager has no known fix available.

Affected products

  • MDJM Event Management before 1.7.8.5
  • Mobile Events Manager Mobile Events Manager through 1.4.8.3

Timeline

  • 2026-09-11: disclosed: Publicly published
  • 2026-09-13: patched: MDJM Event Management fixed in version 1.7.8.5
  • 2026-09-13: advisory: CVE-2026-88802 published

References