The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to the absence of a capability check in the 'custom_fields_controller' function in versions up to 1.7.8.1. This vulnerability allows unauthenticated attackers to delete arbitrary custom event fields.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.