plugin

Mobile Dj Manager Vulnerabilities

10 known security issues reported for the Mobile Dj Manager WordPress plugin. Most recent disclosed Jul 22, 2026.

4 high 3 medium

Running Mobile Dj Manager on your site? Check whether your installed version is affected.

Scan your site free

MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers

high

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of ser...

CVSS:
8.8
Affected:
up to 1.7.8.4
Fixed in:
1.7.8.5
Disclosed:
Jul 22, 2026

CVE-2026-15017 on NVD →

MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter

high

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers...

CVSS:
7.2
Affected:
up to 1.7.8.3
Fixed in:
1.7.8.4
Disclosed:
Jun 5, 2026

CVE-2026-7537 on NVD →

Mobile DJ Manager - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion vulnerability

medium

Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion vulnerability

CVSS:
5.3
Affected:
up to 1.7.8.1
Fixed in:
1.7.8.2
Disclosed:
Mar 7, 2026

MDJM Event Management <= 1.7.8.1 - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion

medium

The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_fields_controller' function in all versions up to, and including, 1.7.8.1. This makes it possible for unauthenticated attackers to delete arbitrary custom event fields via the...

CVSS:
5.3
Affected:
up to 1.7.8.1
Fixed in:
1.7.8.2
Disclosed:
Mar 6, 2026

CVE-2026-1650 on NVD →

MDJM Event Management [mobile-dj-manager] <= 1.7.6 (unfixed)

unknown

[en] Missing Authorization vulnerability in MDJM Mobile DJ Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile DJ Manager: from n/a through 1.7.6.

Affected:
up to 1.7.6
Fix:
No patched version reported
Disclosed:
Jun 27, 2025

CVE-2025-52824 on NVD →

MDJM Event Management <= 1.7.6 - Authenticated (Subscriber+) Privilege Escalation

high

The MDJM Event Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.6. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the mdjm_validate_client_profile AJAX action. T...

CVSS:
8.8
Affected:
up to 1.7.6
Fix:
No patched version reported
Disclosed:
Jun 23, 2025

CVE-2025-52824 on NVD →

MDJM Event Management [mobile-dj-manager] < 1.7.5.3

unknown

[en] Deserialization of Untrusted Data vulnerability in MDJM MDJM Event Management allows Object Injection. This issue affects MDJM Event Management: from n/a through 1.7.5.2.

Affected:
up to 1.7.5.3
Fixed in:
1.7.5.3
Disclosed:
Apr 1, 2025

CVE-2025-31074 on NVD →

MDJM Event Management <= 1.7.5.2 - Authenticated (Subscriber+) PHP Object Injection

high

The MDJM Event Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.7.5.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the...

CVSS:
8.8
Affected:
up to 1.7.5.2
Fixed in:
1.7.5.3
Disclosed:
Mar 28, 2025

CVE-2025-31074 on NVD →

MDJM Event Management [mobile-dj-manager] < 1.7.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MDJM MDJM Event Management allows Reflected XSS. This issue affects MDJM Event Management: from n/a through 1.7.5.5.

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Jan 24, 2025

CVE-2025-22714 on NVD →

MDJM Event Management <= 1.7.5.6 - Reflected Cross-Site Scripting

medium

The MDJM Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 1.7.5.6
Fixed in:
1.7.6
Disclosed:
Jan 15, 2025

CVE-2025-22714 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database