Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash. | |
| Title | MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-13T20:06:37.230Z
Reserved: 2026-09-10T08:28:56.727Z
Link: CVE-2026-88802
No data.
Status : Received
Published: 2026-09-13T21:17:02.323
Modified: 2026-09-13T21:17:02.323
Link: CVE-2026-88802
No data.
OpenCVE Enrichment
No data.
No weakness.