PT-2026-23811 · WordPress · Mdjm Event Management

Abhirup Konwar

·

Published

2026-03-07

·

Updated

2026-03-07

·

CVE-2026-1650

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MDJM Event Management plugin for WordPress versions prior to 1.7.8.2
Description The MDJM Event Management plugin for WordPress has a flaw that allows unauthorized modification of data. This is due to a missing capability check within the custom fields controller function. Unauthenticated attackers can delete arbitrary custom event fields by manipulating the 'delete custom field' and id parameters.
Recommendations Update the MDJM Event Management plugin to version 1.7.8.2 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1650

Affected Products

Mdjm Event Management