SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-88802

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MDJM Event Management and Mobile Events Manager plugins for WordPress are vulnerable to unauthorized post deletions due to a lack of capability checks, nonces, and record type validation. This flaw allows unauthenticated attackers to permanently delete any post, page, or media attachment, leading to potential data loss and disruption. WordPress site administrators using these plugins should prioritize immediate updates to versions 1.7.8.5 and 1.4.8.4 or later to mitigate this risk.

CVE
CVE-2026-88802
Severity
HIGH
CVSS
7.5
EPSS
0.23%
WordPress

Original NVD Description

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.