CVE-2026-88802 PUBLISHED

MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion

Assigner: WPScan
Reserved: 10.09.2026 Published: 13.09.2026 Updated: 14.09.2026

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 7.5

Product Status

Vendor Unknown
Product MDJM Event Management
Versions Default: unaffected
  • affected from 0 to 1.7.8.5 (excl.)
Vendor Unknown
Product Mobile Events Manager
Versions Default: unknown
  • affected from 0 to 1.4.8.3 (incl.)

Credits

  • Enrico Marcolini (Dottor Marc) finder
  • Claudio Marchesini (Dottor Marc) finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE