Description
Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile DJ Manager: from n/a through <= 1.7.8.3.
Published: 2025-06-27
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves a missing authorization check in the Mobile DJ Manager plugin, allowing an attacker to exploit incorrectly configured access controls. Because the plugin fails to enforce proper permission checks, a user who gains access to the plugin’s administrative interface can elevate privileges and perform actions reserved for administrators. This exposure can lead to unauthorized content manipulation, configuration changes, or further exploitation of the WordPress site.

Affected Systems

MDJM’s Mobile DJ Manager plugin for WordPress, affecting all installations running versions n/a through 1.7.8.3. All sites using earlier releases are impacted unless they have performed an update to a later release. The plugin runs within the WordPress environment, so any site hosting the plugin is potentially at risk.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% shows a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the web interface of the plugin, where an attacker can submit crafted requests that bypass the missing authorization check. Once an attacker gains an account with a role that can reach the plugin, privilege escalation can occur without authentication, making the condition of gaining initial access a prerequisite. The absence of publicly disclosed exploits suggests that the window for exploitation is still narrow, but the high severity warrants immediate remediation.

Generated by OpenCVE AI on April 30, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Mobile DJ Manager plugin to any available release newer than 1.7.8.3.
  • Ensure that the plugin’s access control settings are configured so that only administrator accounts can perform privileged actions within the plugin.
  • Restrict access to the plugin’s administrative pages to authenticated administrators, for example by adding IP whitelisting or additional authentication checks if immediate upgrade is not possible.

Generated by OpenCVE AI on April 30, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19313 Missing Authorization vulnerability in MDJM Mobile DJ Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile DJ Manager: from n/a through 1.7.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in MDJM Mobile DJ Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile DJ Manager: from n/a through 1.7.6. Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile DJ Manager: from n/a through <= 1.7.8.3.
Title WordPress Mobile DJ Manager plugin <= 1.7.6 - Privilege Escalation Vulnerability WordPress Mobile DJ Manager plugin <= 1.7.8.3 - Privilege Escalation vulnerability
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 12:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in MDJM Mobile DJ Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile DJ Manager: from n/a through 1.7.6.
Title WordPress Mobile DJ Manager plugin <= 1.7.6 - Privilege Escalation Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:27:31.634Z

Reserved: 2025-06-19T10:03:43.798Z

Link: CVE-2025-52824

cve-icon Vulnrichment

Updated: 2025-06-27T13:14:24.573Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T12:15:44.170

Modified: 2026-04-23T15:32:14.590

Link: CVE-2025-52824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:45:26Z

Weaknesses