Vulnerability Description
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-88802?
CVE-2026-88802 is a vulnerability with a CVSS score of 7.5 (HIGH). The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently...
How severe is CVE-2026-88802?
CVE-2026-88802 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-88802?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.