Vulnerability Description
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers, with administrator-level access and above, to upload files that may be executable, which makes remote code execution possible.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/d0n601/CVE-2026-7537
- https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.2/includ
- https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.2/includ
- https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.3/includ
- https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.3/includ
- https://plugins.trac.wordpress.org/browser/mobile-dj-manager/trunk/includes/admi
- https://plugins.trac.wordpress.org/browser/mobile-dj-manager/trunk/includes/admi
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old
- https://ryankozak.com/posts/cve-2026-7537/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/42f37a41-deff-4b17-94d
FAQ
What is CVE-2026-7537?
CVE-2026-7537 is a vulnerability with a CVSS score of 7.2 (HIGH). The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, ...
How severe is CVE-2026-7537?
CVE-2026-7537 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7537?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.