MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers
high
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of ser...
- CVSS:
- 8.8
- Affected:
- up to 1.7.8.4
- Fixed in:
- 1.7.8.5
- Disclosed:
- Jul 22, 2026
CVE-2026-15017 on NVD →
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
high
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers...
- CVSS:
- 7.2
- Affected:
- up to 1.7.8.3
- Fixed in:
- 1.7.8.4
- Disclosed:
- Jun 5, 2026
CVE-2026-7537 on NVD →
Mobile DJ Manager - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion vulnerability
medium
Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion vulnerability
- CVSS:
- 5.3
- Affected:
- up to 1.7.8.1
- Fixed in:
- 1.7.8.2
- Disclosed:
- Mar 7, 2026
MDJM Event Management <= 1.7.8.1 - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion
medium
The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_fields_controller' function in all versions up to, and including, 1.7.8.1. This makes it possible for unauthenticated attackers to delete arbitrary custom event fields via the...
- CVSS:
- 5.3
- Affected:
- up to 1.7.8.1
- Fixed in:
- 1.7.8.2
- Disclosed:
- Mar 6, 2026
CVE-2026-1650 on NVD →
MDJM Event Management [mobile-dj-manager] <= 1.7.6 (unfixed)
unknown
[en] Missing Authorization vulnerability in MDJM Mobile DJ Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile DJ Manager: from n/a through 1.7.6.
- Affected:
- up to 1.7.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-52824 on NVD →
MDJM Event Management <= 1.7.6 - Authenticated (Subscriber+) Privilege Escalation
high
The MDJM Event Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.6. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the mdjm_validate_client_profile AJAX action. T...
- CVSS:
- 8.8
- Affected:
- up to 1.7.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 23, 2025
CVE-2025-52824 on NVD →
MDJM Event Management [mobile-dj-manager] < 1.7.5.3
unknown
[en] Deserialization of Untrusted Data vulnerability in MDJM MDJM Event Management allows Object Injection. This issue affects MDJM Event Management: from n/a through 1.7.5.2.
- Affected:
- up to 1.7.5.3
- Fixed in:
- 1.7.5.3
- Disclosed:
- Apr 1, 2025
CVE-2025-31074 on NVD →
MDJM Event Management <= 1.7.5.2 - Authenticated (Subscriber+) PHP Object Injection
high
The MDJM Event Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.7.5.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the...
- CVSS:
- 8.8
- Affected:
- up to 1.7.5.2
- Fixed in:
- 1.7.5.3
- Disclosed:
- Mar 28, 2025
CVE-2025-31074 on NVD →
MDJM Event Management [mobile-dj-manager] < 1.7.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MDJM MDJM Event Management allows Reflected XSS. This issue affects MDJM Event Management: from n/a through 1.7.5.5.
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Jan 24, 2025
CVE-2025-22714 on NVD →
MDJM Event Management <= 1.7.5.6 - Reflected Cross-Site Scripting
medium
The MDJM Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 1.7.5.6
- Fixed in:
- 1.7.6
- Disclosed:
- Jan 15, 2025
CVE-2025-22714 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database