Impact
A flaw in the MDJM Event Management and Mobile Events Manager WordPress plugins allows an attacker to permanently delete any post, page or media attachment without authentication. The plugins fail to verify user capability, deny a nonce performing a deletion. Because the request bypasses the normal WordPress trash mechanism, the content is irrevocably removed from the site.
Affected Systems
All installations of MDJM Event Management prior to version 1.7.8.5 and of Mobile Events Manager up to and including version 1.4.8.3 are affected. These plugins are widely deployed on WordPress sites for event and mobile event management.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating high severity. An unauthenticated attacker can trigger a deletion by sending a crafted HTTP request to the playlist entry removal endpoint; no nonce or capability verification is performed. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Consequently, sites running vulnerable versions should prioritize immediate remediation to prevent accidental or malicious data loss.
OpenCVE Enrichment