Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | CWE-862 |
| Metrics |
ssvc
|
Mon, 14 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash. | |
| Title | MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-14T12:38:51.859Z
Reserved: 2026-09-10T08:28:56.727Z
Link: CVE-2026-88802
Updated: 2026-09-14T12:36:47.993Z
Status : Received
Published: 2026-09-13T21:17:02.323
Modified: 2026-09-14T13:19:00.617
Link: CVE-2026-88802
No data.
OpenCVE Enrichment
Updated: 2026-09-14T13:15:03Z
-
CWE-862
Missing Authorization