CVE-2026-88802
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 13, 2026
Vendor
unknown
Description
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.