PT-2026-47127 · WordPress · Mdjm Event Management
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MDJM Event Management plugin for WordPress versions prior to 1.7.8.4
Description
The plugin allows arbitrary file upload because it does not perform validation on the file type, extension, or MIME type of uploaded files. This issue occurs within the
mdjm send comm email() function. Authenticated attackers with administrator-level access or higher can exploit this to upload executable files, potentially leading to remote code execution.Recommendations
Update the plugin to a version later than 1.7.8.3.
As a temporary workaround, restrict access to the
mdjm send comm email() function to minimize the risk of exploitation.Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mdjm Event Management