UNKNOWN (0.0)
    Plugin

    Unauthorized Data Modification in MDJM Event Management Plugin

    Published Date: 3/7/2026
    CVE ID: CVE-2026-1650

    Summary

    The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to the absence of a capability check in the 'custom_fields_controller' function in versions up to 1.7.8.1. This vulnerability allows unauthenticated attackers to delete arbitrary custom event fields.

    Vulnerability Details

    The MDJM Event Management plugin's 'custom_fields_controller' function lacks proper capability checks, which should restrict access to sensitive operations. As a result, attackers can exploit this flaw by sending crafted requests to delete custom event fields without requiring authentication. This is primarily facilitated through the 'delete_custom_field' and 'id' parameters, allowing manipulation of data that should be protected by user permissions. Such vulnerabilities expose WordPress sites to potential data integrity issues, as unauthorized users can perform actions reserved for authenticated users with appropriate roles. The lack of capability checks is a common security oversight, often leading to significant operational disruptions if exploited. Addressing this issue involves reinforcing permission checks and updating the plugin to a secure version.

    Recommendations

    Administrators should immediately restrict access to the vulnerable functionality by employing web application firewalls or security plugins with customizable request rules. It's also critical to review user roles and capabilities regularly to ensure only authorized users have access to sensitive functions.

    Available Fixes

    Last Updated: 3/10/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More